cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
547
Views
0
Helpful
1
Replies

"othermalware" verdict??

Hey guys,

Where can I get more info on this "othermalware" verdict?

1469732787.499 133 172.16.7.10 TCP_MISS_SSL/200 0 TCP_CONNECT 208.46.117.198:443 "domain\user" DIRECT/208.46.117.198 - DECRYPT_WBRS_7-DefaultGroup-DefaultGroup-DefaultGroup-NONE-NONE-DefaultGroup <IW_infr,-4.0,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,IW_infr,-,"-","othermalware","Unknown","Unknown","-","-",0.00,0,Local,"-","-",-,"-",-,-,"-","-"> -

Its app, so I'm not getting a web page returned, and nothing is showing up in the Webroot/Sophos/AMP logs.

Ken

1 Reply 1

Handy Putra
Cisco Employee
Cisco Employee

From the accesslogs shown, the "othermalware" looks like falls under the Web Reputation Filter Threat Type.

Normally if its consider as other malware category means that this category is used to catch all other malware and suspicious behavior that does not exactly fit in one of the other defined categories.

Or could be false positive case as well.

Do you see any further traffic in the accesslogs after it is being decrypted?