trojan/Win32.deceiver.d - False Positive?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

trojan/Win32.deceiver.d - False Positive?

L0 Member

I have noticed that PA NGFW sees this threat trojan/Win32.deceiver.d using Logon.exe from PCs in a specific zone (zone 1) going to our DCs that happen to be in a different zone (zone 2).  I have had a couple of users say they have to type in their credentials a couple of times but we blamed DUO for that.  In the Threat log I see only a few of the PCs in zone 1 application: ms-ds-smbv3, Type: virus or wildfire-virus, using port 445.  When I look in the Wildfire Submissions:  File name: logon.exe action: block.

 

We have Malwarebytes and Cortex - when I scan those machines - they come back clean.

 

Anyone else having this issue?

1 REPLY 1

Cyber Elite

Maybe the logon.exe is dynamic and each time is different and Wildfire need to scan it. You can create rule that matches the app, the url and attach wildfire profile with not a "Hold" mode and also check the logs that it is not the Inline ML Wildfire that uses prebuild AI models for scanning without checking the Wildfire cloud.

 

See:  "The system applies the fall back policy rule configured by the administrator, which determines whether to enable (permissive) or block (protective) the file."

 

File Handling and Analysis in Advanced WildFire

 

Hold Mode for WildFire Real-Time Signature Lookup

 

Advanced WildFire Inline ML

  • 128 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!