<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR flagged malicious macros in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578657#M6195</link>
    <description>&lt;P&gt;&lt;BR /&gt;Hi team &lt;BR /&gt;Cortex XDR keeps generates hundreds of alerts due to suspicious macro detected in my network.&amp;nbsp;&lt;BR /&gt;Severity : High&lt;BR /&gt;Alert Source :&amp;nbsp;XDR Agent&lt;BR /&gt;Action :&amp;nbsp;&lt;SPAN&gt;Detected (Post Detected)&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="single-item-wrapper ng-star-inserted"&gt;Category : Malware&lt;BR /&gt;Extensions : .xls&amp;nbsp;&lt;SPAN class="text ng-star-inserted" title="3CEA66E1.tmp"&gt;.tmp&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;.xlt&amp;nbsp;&amp;nbsp;.xar&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;Seems Cortex deletes all kind of files that has macros , but in reality those are not malicious.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"alerts_table": {&lt;BR /&gt;"alert_json": {&lt;BR /&gt;"action_country": [&lt;BR /&gt;"UNKNOWN"&lt;BR /&gt;],&lt;BR /&gt;"action_file_extension": [&lt;BR /&gt;".xls"&lt;BR /&gt;],&lt;BR /&gt;"action_file_name": [&lt;BR /&gt;"5406272E.xls"&lt;BR /&gt;],&lt;BR /&gt;"action_file_path": [&lt;BR /&gt;"C:\\Users\\XXXXX\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.MSO\\5406272E.xls"&lt;BR /&gt;],&lt;BR /&gt;"action_file_sha256": [&lt;BR /&gt;"b765f574a58676191bfdd5876ba7fc41d749197b9b8d1d48381bd8b057a8aa40"&lt;BR /&gt;],&lt;BR /&gt;"action_process_signature_status": [&lt;BR /&gt;"SIGNATURE_UNAVAILABLE"&lt;BR /&gt;],&lt;BR /&gt;"actor_effective_username": [&lt;BR /&gt;"N/A"&lt;BR /&gt;],&lt;BR /&gt;"actor_process_signature_status": [&lt;BR /&gt;"SIGNATURE_UNAVAILABLE"&lt;BR /&gt;],&lt;BR /&gt;"agent_data_collection_status": false,&lt;BR /&gt;"agent_device_domain": "XXXX",&lt;BR /&gt;"agent_fqdn": "XXXXXX",&lt;BR /&gt;"agent_hostname": "XXXXXX",&lt;BR /&gt;"agent_id": "9d0d8ee73cfc4be39ce6a3dde57ddfcb",&lt;BR /&gt;"agent_ip_addresses": [&lt;BR /&gt;&lt;BR /&gt;],&lt;BR /&gt;"agent_is_vdi": false,&lt;BR /&gt;"agent_os_sub_type": "10.0.19045",&lt;BR /&gt;"agent_os_type": "AGENT_OS_WINDOWS",&lt;BR /&gt;"agent_version": "8.2.1.47908",&lt;BR /&gt;"alert_action_status": "POST_DETECTED",&lt;BR /&gt;"alert_category": "Malware",&lt;BR /&gt;"alert_description": "Suspicious macro detected",&lt;BR /&gt;"alert_ingest_status": "READY",&lt;BR /&gt;"alert_is_fp": false,&lt;BR /&gt;"alert_name": "WildFire Malware",&lt;BR /&gt;"alert_source": "TRAPS",&lt;BR /&gt;"alert_type": "Unclassified",&lt;BR /&gt;"association_strength": [&lt;BR /&gt;50&lt;BR /&gt;],&lt;/P&gt;</description>
    <pubDate>Wed, 28 Feb 2024 14:51:23 GMT</pubDate>
    <dc:creator>chawki</dc:creator>
    <dc:date>2024-02-28T14:51:23Z</dc:date>
    <item>
      <title>Cortex XDR flagged malicious macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578657#M6195</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi team &lt;BR /&gt;Cortex XDR keeps generates hundreds of alerts due to suspicious macro detected in my network.&amp;nbsp;&lt;BR /&gt;Severity : High&lt;BR /&gt;Alert Source :&amp;nbsp;XDR Agent&lt;BR /&gt;Action :&amp;nbsp;&lt;SPAN&gt;Detected (Post Detected)&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="single-item-wrapper ng-star-inserted"&gt;Category : Malware&lt;BR /&gt;Extensions : .xls&amp;nbsp;&lt;SPAN class="text ng-star-inserted" title="3CEA66E1.tmp"&gt;.tmp&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;.xlt&amp;nbsp;&amp;nbsp;.xar&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;Seems Cortex deletes all kind of files that has macros , but in reality those are not malicious.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"alerts_table": {&lt;BR /&gt;"alert_json": {&lt;BR /&gt;"action_country": [&lt;BR /&gt;"UNKNOWN"&lt;BR /&gt;],&lt;BR /&gt;"action_file_extension": [&lt;BR /&gt;".xls"&lt;BR /&gt;],&lt;BR /&gt;"action_file_name": [&lt;BR /&gt;"5406272E.xls"&lt;BR /&gt;],&lt;BR /&gt;"action_file_path": [&lt;BR /&gt;"C:\\Users\\XXXXX\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.MSO\\5406272E.xls"&lt;BR /&gt;],&lt;BR /&gt;"action_file_sha256": [&lt;BR /&gt;"b765f574a58676191bfdd5876ba7fc41d749197b9b8d1d48381bd8b057a8aa40"&lt;BR /&gt;],&lt;BR /&gt;"action_process_signature_status": [&lt;BR /&gt;"SIGNATURE_UNAVAILABLE"&lt;BR /&gt;],&lt;BR /&gt;"actor_effective_username": [&lt;BR /&gt;"N/A"&lt;BR /&gt;],&lt;BR /&gt;"actor_process_signature_status": [&lt;BR /&gt;"SIGNATURE_UNAVAILABLE"&lt;BR /&gt;],&lt;BR /&gt;"agent_data_collection_status": false,&lt;BR /&gt;"agent_device_domain": "XXXX",&lt;BR /&gt;"agent_fqdn": "XXXXXX",&lt;BR /&gt;"agent_hostname": "XXXXXX",&lt;BR /&gt;"agent_id": "9d0d8ee73cfc4be39ce6a3dde57ddfcb",&lt;BR /&gt;"agent_ip_addresses": [&lt;BR /&gt;&lt;BR /&gt;],&lt;BR /&gt;"agent_is_vdi": false,&lt;BR /&gt;"agent_os_sub_type": "10.0.19045",&lt;BR /&gt;"agent_os_type": "AGENT_OS_WINDOWS",&lt;BR /&gt;"agent_version": "8.2.1.47908",&lt;BR /&gt;"alert_action_status": "POST_DETECTED",&lt;BR /&gt;"alert_category": "Malware",&lt;BR /&gt;"alert_description": "Suspicious macro detected",&lt;BR /&gt;"alert_ingest_status": "READY",&lt;BR /&gt;"alert_is_fp": false,&lt;BR /&gt;"alert_name": "WildFire Malware",&lt;BR /&gt;"alert_source": "TRAPS",&lt;BR /&gt;"alert_type": "Unclassified",&lt;BR /&gt;"association_strength": [&lt;BR /&gt;50&lt;BR /&gt;],&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 14:51:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578657#M6195</guid>
      <dc:creator>chawki</dc:creator>
      <dc:date>2024-02-28T14:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR flagged malicious macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578663#M6196</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;From my part, I have experienced the same issue in various tenants where alerts are triggered by WildFire, as it has classified a malicious macro with the following hash:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;9eec5eadef0a1883a2177e016ff2a0ddc9fd3cdb0549554043079b672a181228&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I opened a support case this morning, but I have not received a response yet&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 15:12:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578663#M6196</guid>
      <dc:creator>Daniel_Ponce</dc:creator>
      <dc:date>2024-02-28T15:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR flagged malicious macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578664#M6197</link>
      <description>&lt;P&gt;Same here. I opened a case and still waiting for support.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 15:14:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578664#M6197</guid>
      <dc:creator>chawki</dc:creator>
      <dc:date>2024-02-28T15:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR flagged malicious macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578667#M6198</link>
      <description>&lt;P&gt;Same problem here, we are having this issue from 2 AM and still continue triggering the alerts&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 15:22:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578667#M6198</guid>
      <dc:creator>InakiMartinez</dc:creator>
      <dc:date>2024-02-28T15:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR flagged malicious macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578817#M6208</link>
      <description>&lt;P&gt;I had the same issue and opened a case. Support told me yesterday that the macro is analysed again and that the verdict for the hash&amp;nbsp;&lt;SPAN&gt;9eec5eadef0a1883a2177e016ff2a0ddc9fd3cdb0549554043079b672a181228 was changed back to benign. I had no issues since Palo Alto changed the verdict to benign&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 09:55:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578817#M6208</guid>
      <dc:creator>micomi</dc:creator>
      <dc:date>2024-02-29T09:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR flagged malicious macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578828#M6210</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The hit was due to Wildfire Verdict which uses Machine Learning to analyze the file. Our Team has investigated the issue and changed the verdict to&amp;nbsp;&lt;SPAN&gt;Benign:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;The sample is safe and does not exhibit malicious behavior.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Verdicts that you suspect are either false positives or false negatives can be submitted to the Palo Alto Networks threat team for additional analysis via Support Case or reaching out to SE.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 11:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-flagged-malicious-macros/m-p/578828#M6210</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-02-29T11:39:13Z</dc:date>
    </item>
  </channel>
</rss>

