WildFire Report With Verdict Malware Passed

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

WildFire Report With Verdict Malware Passed

Hello,

 

WildFire analysed a file considered as Malware

 

But the Dynamic analysis in the same report shows that it's Benign, How this could happen ?! 

and Traps allowed this file and considered this as notification, is there any explanation

 

112121212122222222222.PNG

4 REPLIES 4

L0 Member
Fixed? smiley_smile.png

@Mohammad.Qawasmeh 

The answer to your question is not very simple. There are several moving parts inline that could affect, and display the behavior you see. It would be recommended to open a ticket with support, who can assist in analyzing the issue, and escalate if needed.

Thanks

Cyber Elite
Cyber Elite

@Mohammad.Qawasmeh,

What likely happend is local analysis analyzed the file due to WildFire not having a verdict for the file hash, and that analysis didn't show any problems. When that file was later uploaded to WildFire the sandbox environment recognized malicious activity and labeled it as malware. Due to the file already being allowed to run, the only thing you'll get is a notification saying that it allowed this to run.

The good news is the hash is now known as malicious and it can't be run on any other device as long as they can check the hash verdict status with WildFire, so even though it allowed it on one machine it will block it going forward. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!