cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
870
Views
0
Helpful
3
Replies

notification for Vista file on firepower

Samer R. Saleem
Level 4
Level 4

Hi,

 

I'm getting notifications about the file detection name below when one of the users connected by VPN and tried to download some Medical software package that belongs to Vista application

W32.19E0AFBF46-63.SBX.VIOC

 

why the firepower detects it like a malware?

how to know the affect of the malware if its real?

note: we have also McAfee antivirus and it didn't detect it as a malware even though we have been using this application on many computers

3 Replies 3

Check in Analysis > File Events and see the disposition or the file. From
Talos it says for this signature ( This example may contain a partial hash
of the SHA256 that matched. )

If you are sure that is safe, you can whitelist

thanks for your reply, so in case of partial match in the signatures it will be considered malware?

 

is there a website to check signatures?

As this probably is a false positive I would suggest to contact tac.
Else you are stuck with virustotal or other third party solutions to check the file.

br, Micke
Review Cisco Networking for a $25 gift card