04-13-2023 07:47 AM
Is anyone else seeing large amount of Malware blocking on their MX?
Is this a false positive related to Microsoft ?
04-13-2023 08:33 AM
Sure thing normally it would take one business day for them to revert back
04-13-2023 08:06 AM
New to the company and I received this alert and immediately scared me. Then I saw it originated from Microsoft and did a little googling and found this thread. Phew
04-13-2023 08:08 AM
Getting that alert saying 100s or 1000s of possible malicious downloads is certainly panic-inducing!
04-13-2023 08:10 AM
Indeed at this point we are so fed up with those email that we took ourselves out from that specific email list. LOL
04-13-2023 08:11 AM
04-13-2023 08:17 AM
Glad we can all collaborate and compare so quickly in the Community. Great relief!
04-13-2023 08:24 AM
Just had an additional file start popping up.
URL root is: 1d.tlu.dl.delivery.mp.microsoft.com
File: W32.0E9CF9601C.RET.SBX.TG
SHA256: 0e9cf9601c14abd31bb02adfa0986ceb78af596cbd991e6cad89fe80ea959abd
04-13-2023 08:27 AM
Yes, I'm seeing it also.
04-13-2023 08:28 AM
Follow along on this thread for updates: https://community.meraki.com/t5/Meraki-Service-Notices/Security-Center-False-Positive-Alert-April-13th-2023/ba-p/191287
04-13-2023 08:29 AM
This one too
8dea8123-fd8f-492c-9c2d-7cdfab740447
04-13-2023 08:29 AM
Saw this too on multiple customers. None of our AVs have found anything malicious that would relate to this alert from Meraki.
04-13-2023 08:38 AM
This is not new believe it or not. These windows updates have been reported months ago to Meraki. I have an open ticket from months ago trying to figure this out. Meraki on the backend is reporting these as malware, but it wasnt being reported to the dashboard and/or email alerts. Something changed today and now its actually reporting so I might finally have some resolution to my open ticket.
How I discovered the problem is that I enabled syslog logging and sent all my logs to papertrail. I then setup an alert on when malware was downloaded and I kept getting these alerts in papertrail. Heres the original ticket.
There was never a resolution, meraki support could not help and they said their backend team was involved with the case. I was never able to forcibly recreate the issue, so they were never able to resolve it. This was happening across many clients with the same error/issue.
Heres a sample from 2 days ago from my papertrail app that went unreported to the dashboard and/or email alert.
Apr 11 10:20:04 98.151.19.171 logger <134>1 1681244404.194824387 OLGC_Firewall security_event security_filtering_file_scanned url=http://1d.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ade20ec6-c563-480b-ad73-40580d3f2b72?P1=1681245007&P2=404&P3=2&P4=X4AhVcAJt9jaRV%2fQCoOfA68Y3tgXZY4Hhvr8JWM6pe5%2fEIEDZAOWhdj0CK60cr4uGAgFEfe0%2b5r5q7kjJ%2foh3w%3d%3d src=192.168.1.192:54486 dst=209.197.3.8:80 mac=30:D1:6B:F1:7E:E7 name='' sha256=fc46caae796a5bfe5eb2a814d8f97fc91e6f710f68ca00832ccd7171fb550151 disposition=malicious action=block
I think my issue might finally get resolved now that its reporting to the dashboard and/or email alerts and its widespread.
04-13-2023 08:42 AM
Ya looking at the timeline in my security tools on one of the devices supposedly affected there is nothing going on except for attempts at windows updates.
so unless MS is compromised this is almost certainly a false positive
04-13-2023 08:48 AM
Where did my post go?
04-13-2023 08:48 AM
This is not new believe it or not. These windows updates have been reported months ago to Meraki. I have an open ticket from months ago trying to figure this out. Meraki on the backend is reporting these as malware, but it wasnt being reported to the dashboard and/or email alerts. Something changed today and now its actually reporting so I might finally have some resolution to my open ticket.
How I discovered the problem is that I enabled syslog logging and sent all my logs to papertrail. I then setup an alert on when malware was downloaded and I kept getting these alerts in papertrail. Heres the original ticket.
There was never a resolution, meraki support could not help and they said their backend team was involved with the case. I was never able to forcibly recreate the issue, so they were never able to resolve it. This was happening across many clients with the same error/issue.
Heres a sample from 2 days ago from my papertrail app that went unreported to the dashboard and/or email alert.
Apr 11 10:20:04 98.151.25.111 logger <134>1 1681244404.194824387 Firewall security_event security_filtering_file_scanned url=http://1d.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ade20ec6-c563-480b-ad73-40580d...?P1=1681245007&P2=404&P3=2&P4=X4AhVcAJt9jaRV%2fQCoOfA68Y3tgXZY4Hhvr8JWM6pe5%2fEIEDZAOWhdj0CK60cr4uGAgFEfe0%2b5r5q7kjJ%2foh3w%3d%3d src=192.168.1.192:54486 dst=209.197.3.8:80 mac=30:D1:6B:F1:7E:E7 name='' sha256=fc46caae796a5bfe5eb2a814d8f97fc91e6f710f68ca00832ccd7171fb550151 disposition=malicious action=block
I think my issue might finally get resolved now that its reporting to the dashboard and/or email alerts and its widespread.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide