06-09-2020 11:11 PM
Lately we have seen number of blocked connection for Teams.nuspec. Virus Total report for Destination IP is shows clean.
06-10-2020 05:59 AM
We've seen a bunch of these as well from when we first started using Microsoft Teams.
Since then, we have bursts of them. Yesterday was a bad day. I think they are false positives as well, but I'd love to better understand why we are getting them.
06-10-2020 12:20 PM
Please open a Support case so it can be looked at in detail.
06-10-2020 12:55 PM - edited 06-11-2020 12:07 AM
I have also been seeing this file across some of our customers that we monitor. We will get Virus alerts for that file that WildFire is flagging. I don't think this is a virus and is more than likely a false+. I was looking into this a little further and found out that the file is being hosted here https://chocolatey.org/packages/microsoft-teams#files. The file passes all checks on their site which you can view the Registry Snapshot by going to the following link https://gist.github.com/choco-bot/94b957a0ae5da9a075eb88dd4c890bd9. If I get some time I will download the file on my VM and run it through some checks and will update. I agree with the above comment and open a case so that Palo can take a look into this further. Have a good day!
06-11-2020 11:41 AM
We are looking at it further to understand what is causing the continued FP detections.
All the signatures listed in the screenshot are now disabled.
06-12-2020 06:28 AM
still false-positives for threat id: 346399143 filename: Teams.nuspec - Virus/Win32.WGeneric.akfdwd
Content version: Antivirus-3376-3887
06-12-2020 06:56 AM
The signature 346399143 was disabled 06/11/2020
06-12-2020 10:57 AM
The signature is removed beginning with Antivirus version 3377-3888
06-16-2020 05:19 AM
Another: teams.nuspec - Virus/Win32.WGeneric.a
signature: 346947453 (in Antivirus-3380-3891)
06-16-2020 05:34 AM
Same! We've received a bunch of those as well.
The virus 346947453(346947453) was detected at Teams.nuspec
346947453 was disabled and is now removed from Antivirus 3381
07-27-2020 10:10 PM
And it seems to be back again - Threat ID #356771745 Virus Teams.nuspec detected via an Antivirus profile.Excluded it and raising a note with PAN.
07-28-2020 02:00 PM
356771745 was disabled and will be removed from tomorrow's release of the Antivirus signature package.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!