JS/Trojan.redirector.cay false postive?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

JS/Trojan.redirector.cay false postive?

L4 Transporter

Hello,

Starting from what appears to be right after pattern update 683-936 was committed - we began receiving a very substantial amount of alerts from multiple internal "victims" for this Trojan.  I am still investigating this internally.  Has anyone else had a large amount of activity on this signature starting recently? Looking to verify if this is a false positive or not.  Other AV protection layers are not reporting this type of activity.  Thanks.

Name:JS/Trojan.redirector.cay
ID:250007
Severity:
Description:This signature detected JS/Trojan.redirector.cay

1 ACCEPTED SOLUTION

Accepted Solutions

Content version 686-XXX has the fix.

When we get a report of a false positive we usually ask for the following.

show system info

-- To  see all currently installed software.

Threat logs that you believe to be a false positive.

Traffic logs for the IP address identified in the Threat log.

If the firewall is configured to save a PCAP of the packet that triggered the threat we ask for this as well.

If the threat was triggered by a URL or a file download, we would like this information to try and reproduce internally.

Thanks,

Steve Krall

View solution in original post

9 REPLIES 9

Not applicable

I am seeing this as well.  I thought maybe it was a single website, but from the looks of it, I think it just may be a false positive.  I have identified the source IP's as being owned by a company called AppNexus (at least this is our case).  I'm still investigating myself.

Thank you for the update from your end as well.  I updated to the latest version a few minutes ago and no change.  Events still showing up.

Antivirus version684-937 (2012/02/20)

We also have a lot of these. The ones I have examined are from adnxs.com, which appears to be an advertising site. Brightcloud categorizes it as Trustworthy.

We also seem to have URL filtering categorizing a lot of advertisers like atdmt.com and doubleclick.net as malware sites.

Neil Flanagan

Not applicable

We are also seeing a high number of these.  Have the latest and greatest defenitions as well.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!