cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2756
Views
2
Helpful
13
Replies

FP on Microsoft Edge update?

Hey guys, 

Anyone else seeing this:

  • Detection: W32.082827C4A5.RET.SBX.TG
  • File: MicrosoftEdge_X64_112.0.1722.39_112.0.1722.34.exe
  • File path: file:///C%3A/Program%20Files%20%28x86%29/Microsoft/EdgeUpdate/Install/%7BBEA8EA03-94F9-45AB-AC52-0309F5FD1DF3%7D/MicrosoftEdge_X64_112.0.1722.39_112.0.1722.34.exe
  • Detection SHA-256: 082827c4a5582f887901c4cce83a1aa9b8a4eb23835a434fc104bba745172a85

Feels like an FP to me. 

 

Ken 

 

13 Replies 13

We are also seeing a large number of these this morning. 

pmedinac
Cisco Employee
Cisco Employee

Our team is actively looking on this SHA-256 investigation to either discard if it is a FP event or not. Thank you for sharing.

ac513
Level 1
Level 1

Just got FP confirmation from a Cisco Secure Endpoint announcement email about 15 minutes ago.

pmedinac
Cisco Employee
Cisco Employee

Hey,,

 

This SHA-256 is already marked as clean after analysis: 

SHA-256: 082827c4a5582f887901c4cce83a1aa9b8a4eb23835a434fc104bba745172a85

You should see the alerts stop during the next minutes/hours, as soon as the endpoints receive the latest definition updates.

--

Pedro M.

Hi pmedinac

also seeing alerts on 975c0d48c41d2ad76a242d5f7270f4bf8063bb9c753b375ab2c47c9e2060f562. Same/similar issue?

Just got that one too...

Also seeing this SHA-256 detection on our Firepower appliances

My TAC engineer says Talos just poked that one clean too.

pmedinac
Cisco Employee
Cisco Employee

Yeap, I double check and that one (975c0d48c41d2ad76a242d5f7270f4bf8063bb9c753b375ab2c47c9e2060f562) was is also Clean.

Same as the other, it may take some time to get the endpoint updates to stop alerts.

Greetings.

--

Pedro M.

mski7861
Level 1
Level 1

Same issue.  Do we still need to whitelist the SHA256?  Or has Cisco corrected the behavior detection?

pmedinac
Cisco Employee
Cisco Employee

This is already corrected, the endpoints may take some time to get the latest update.

--

Pedro M.

magragen
Level 1
Level 1

Does this have anything to do with the Cisco-Maintained Exclusion list changes that were done yesterday? 

pmedinac
Cisco Employee
Cisco Employee

Nope, this has nothing related to the Cisco-Maintained Exclusion list modified yesterday.

This is just an incorrect conviction that has been fixed at the moment.

--

Pedro M.