04-09-2024 06:01 AM
Last night we started getting GT:JS.Hyena.3.x detections on a number of computers. We are continuing to receive them, over 150 machines so far. Anyone else seeing this?
Solved! Go to Solution.
04-12-2024 05:12 AM
The signature number was 14081197 and it was updated on the 10th around 2300 UTC. Hope that helps.
-Matt
04-09-2024 07:06 AM
TALOS is investigating for a potential FP.
04-09-2024 11:35 AM
Seeing this on a large number of hosts in our environment. Appears to relate to browser updates.
04-10-2024 01:59 AM
had a few boxes pop. no wscript or cscript action either. odd. this looks like a FP
04-10-2024 05:09 AM
Still seeing this on a growing number of endpoints.
04-10-2024 05:41 AM
We also continue to get these - a few hundred more detections throughout the night.
04-10-2024 06:05 AM
I've requested an update from TALOS and also stressed the priority. If you haven't, please open a TAC case as this will help with the prioritization.
04-10-2024 06:08 AM
Thank you Matthew. Yes, we also opened a TAC case yesterday. Last update was from yesterday afternoon.
Hello, Talos is still investigating the issue at hand.
Far as the alerts, you can do the following options:
The options above are only temporary remediations until the false positive issue is fixed and, of course, this is solely your discretion, but I wanted to offer this to you as you mentioned you are receiving numerous alerts in the console.
04-10-2024 06:31 AM
04-10-2024 06:37 AM
I also had a large number of these pop up and opened a file reputation case at Talos but they closed it right away. Has it been confirmed a false positive?
04-10-2024 07:15 AM
As of now, it still hasn't been confirmed as a false positive. I will post again when we hear back from TAC.
04-10-2024 10:24 AM
Opened a TAC case last night. Got detections of this on 5 computers so far since 7:45PM ET last night.
04-10-2024 10:35 AM
TAC case opened here as well. I have been told Talos is aware of the situation.
We have over 250 detections at this point.
04-10-2024 11:04 AM
Just got Secure Endpoint notification
Cisco is aware of the false positive detections related to JS.Hyena.3.xxxx that started at approximately 2024-04-09 18:26 UTC. The signatures involved are being reviewed and Cisco is investigating the root cause. We apologize for any inconvenience this may have caused.
04-10-2024 12:53 PM
Keep securing and being watchful until a response back from Cisco.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide