06-09-2020 11:11 PM
Hi there,
Lately we have seen number of blocked connection for Teams.nuspec. Virus Total report for Destination IP is shows clean.
06-10-2020 05:59 AM
We've seen a bunch of these as well from when we first started using Microsoft Teams.
Since then, we have bursts of them. Yesterday was a bad day. I think they are false positives as well, but I'd love to better understand why we are getting them.
06-10-2020 12:20 PM
Please open a Support case so it can be looked at in detail.
06-10-2020 12:55 PM - edited 06-11-2020 12:07 AM
I have also been seeing this file across some of our customers that we monitor. We will get Virus alerts for that file that WildFire is flagging. I don't think this is a virus and is more than likely a false+. I was looking into this a little further and found out that the file is being hosted here https://chocolatey.org/packages/microsoft-teams#files. The file passes all checks on their site which you can view the Registry Snapshot by going to the following link https://gist.github.com/choco-bot/94b957a0ae5da9a075eb88dd4c890bd9. If I get some time I will download the file on my VM and run it through some checks and will update. I agree with the above comment and open a case so that Palo can take a look into this further. Have a good day!
06-11-2020 11:41 AM
We are looking at it further to understand what is causing the continued FP detections.
All the signatures listed in the screenshot are now disabled.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!