cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3590
Views
0
Helpful
6
Replies

Cisco AMP detecting Firefox 70.0 as Malicious

kgriffen
Level 1
Level 1

Currently downloading Firefox 70.0 from https://www.mozilla.org/en-US/firefox/download/thanks/ is being marked in Cisco AMP for Endpoints as malicious.

1 Accepted Solution

Accepted Solutions

False Positive confirmed by TALOS and the hash is no longer marked as malicious.

 

Thanks,
Matt 

View solution in original post

6 Replies 6

Matthew Franks
Cisco Employee
Cisco Employee

I just downloaded the file you linked.  It had a hash of 

2acb8fbc34a4eecfa8a9d0fe5e0b522a8a1b5dcd97fd52b38464e5a00524197c which is not marked malicious in the AMP database.  Could you provide the hash of the file you downloaded that was detected as malicious?

 

Thanks,

Matt

069edc8e7266e5aa044ca84e76641fc12320186eb8d061f0d74b2f4857922782

And it was marked malicious via the sandbox.

069edc8e7266e5aa044ca84e76641fc12320186eb8d061f0d74b2f4857922782

I've submitted a False Positive review to TALOS for that file.  In the future, you can submit these yourself for a faster turnaround time at https://talosintelligence.com/talos_file_reputation .  Search by the file hash and then, if the disposition is malicious as this one is, click the Submit a File Reputation Ticket here hyperlink.  

 

Thanks,

Matt

Thank you!

False Positive confirmed by TALOS and the hash is no longer marked as malicious.

 

Thanks,
Matt