cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2107
Views
1
Helpful
4
Replies

False positive hit ... or not ? - Solved

Brian Korfitz Miehs
Frequent Visitor
Frequent Visitor

Hi

I'm working with a costumers Sourcefire and ran into this file being blocked by the system.

AAFlash_setup.exe

https://www.virustotal.com/en/file/8e13f9c500757b2822c8c36a5ee32b820ff274e8cbbc9976f0cce096d7e7dd18/analysis/

I can't seem to find any reason anywhere as to why the file is being blocked other that the Sourcefire dosn't like it.

So does it contain malware or is it a false positive ?

And where do i find this infomation because my almighty google didn't help me.

Picture with the hit is attached

//Brian

1 Accepted Solution

Accepted Solutions

Then it must be a false positive.

View solution in original post

4 Replies 4

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

The screenshot you supplied says it is malware ...

I can read and that is really not my problem 😉

My problem is 56 other virus scanners say that this file is clean and the only Sourcefire says it's infected and dosn't show in detail with what.

Brian Korfitz Miehs
Frequent Visitor
Frequent Visitor

I found someone with access to threatgrid and the file was just slightly bad and with no virus.

Then it must be a false positive.

Review Cisco Networking for a $25 gift card