cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
34027
Views
65
Helpful
43
Replies

MX Malware Blocking

AVIF
Community Member

Is anyone else seeing large amount of Malware blocking on their MX?

W32.975C0D48C4.RET.SBX.TG

ArchiveFile

Is this a false positive related to Microsoft ?

43 Replies 43

Sure thing normally it would take one business day for them to revert back

vsanch62
Community Member

New to the company and I received this alert and immediately scared me. Then I saw it originated from Microsoft and did a little googling and found this thread. Phew

Getting that alert saying 100s or 1000s of possible malicious downloads is certainly panic-inducing!

Indeed at this point we are so fed up with those email that we took ourselves out from that specific email list. LOL

TODD BEERS
Level 2
Level 2

Glad we can all collaborate and compare so quickly in the Community. Great relief!

Jameson2
Level 2
Level 2

Just had an additional file start popping up.

URL root is: 1d.tlu.dl.delivery.mp.microsoft.com

File: W32.0E9CF9601C.RET.SBX.TG

SHA256: 0e9cf9601c14abd31bb02adfa0986ceb78af596cbd991e6cad89fe80ea959abd

dayoder
Visitor

Yes, I'm seeing it also.

TODD BEERS
Level 2
Level 2

This one too

8dea8123-fd8f-492c-9c2d-7cdfab740447

SHA2567f4cbddda24faf170473706c062c8957d6bb422b285013c932c61e8dd4efb381
Disposition Clean

TITAN1212
Community Member

Saw this too on multiple customers. None of our AVs have found anything malicious that would relate to this alert from Meraki.

Barakaki
Community Member

This is not new believe it or not. These windows updates have been reported months ago to Meraki. I have an open ticket from months ago trying to figure this out. Meraki on the backend is reporting these as malware, but it wasnt being reported to the dashboard and/or email alerts. Something changed today and now its actually reporting so I might finally have some resolution to my open ticket.

How I discovered the problem is that I enabled syslog logging and sent all my logs to papertrail. I then setup an alert on when malware was downloaded and I kept getting these alerts in papertrail. Heres the original ticket.

image.png

There was never a resolution, meraki support could not help and they said their backend team was involved with the case. I was never able to forcibly recreate the issue, so they were never able to resolve it. This was happening across many clients with the same error/issue.

Heres a sample from 2 days ago from my papertrail app that went unreported to the dashboard and/or email alert.

Apr 11 10:20:04 98.151.19.171 logger <134>1 1681244404.194824387 OLGC_Firewall security_event security_filtering_file_scanned url=http://1d.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ade20ec6-c563-480b-ad73-40580d3f2b72?P1=1681245007&amp;P2=404&amp;P3=2&amp;P4=X4AhVcAJt9jaRV%2fQCoOfA68Y3tgXZY4Hhvr8JWM6pe5%2fEIEDZAOWhdj0CK60cr4uGAgFEfe0%2b5r5q7kjJ%2foh3w%3d%3d src=192.168.1.192:54486 dst=209.197.3.8:80 mac=30:D1:6B:F1:7E:E7 name='' sha256=fc46caae796a5bfe5eb2a814d8f97fc91e6f710f68ca00832ccd7171fb550151 disposition=malicious action=block

I think my issue might finally get resolved now that its reporting to the dashboard and/or email alerts and its widespread.

molan
Community Member

Ya looking at the timeline in my security tools on one of the devices supposedly affected there is nothing going on except for attempts at windows updates.

image.png

so unless MS is compromised this is almost certainly a false positive

Barakaki
Community Member

Where did my post go?

This is not new believe it or not. These windows updates have been reported months ago to Meraki. I have an open ticket from months ago trying to figure this out. Meraki on the backend is reporting these as malware, but it wasnt being reported to the dashboard and/or email alerts. Something changed today and now its actually reporting so I might finally have some resolution to my open ticket.

How I discovered the problem is that I enabled syslog logging and sent all my logs to papertrail. I then setup an alert on when malware was downloaded and I kept getting these alerts in papertrail. Heres the original ticket.

image.png

There was never a resolution, meraki support could not help and they said their backend team was involved with the case. I was never able to forcibly recreate the issue, so they were never able to resolve it. This was happening across many clients with the same error/issue.

Heres a sample from 2 days ago from my papertrail app that went unreported to the dashboard and/or email alert.

Apr 11 10:20:04 98.151.25.111 logger <134>1 1681244404.194824387 Firewall security_event security_filtering_file_scanned url=http://1d.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ade20ec6-c563-480b-ad73-40580d...?P1=1681245007&amp;P2=404&amp;P3=2&amp;P4=X4AhVcAJt9jaRV%2fQCoOfA68Y3tgXZY4Hhvr8JWM6pe5%2fEIEDZAOWhdj0CK60cr4uGAgFEfe0%2b5r5q7kjJ%2foh3w%3d%3d src=192.168.1.192:54486 dst=209.197.3.8:80 mac=30:D1:6B:F1:7E:E7 name='' sha256=fc46caae796a5bfe5eb2a814d8f97fc91e6f710f68ca00832ccd7171fb550151 disposition=malicious action=block

I think my issue might finally get resolved now that its reporting to the dashboard and/or email alerts and its widespread.