We are seeing lot of Teams.nuspec as virus - are they False Positive?

Reply
Highlighted
L0 Member

We are seeing lot of Teams.nuspec as virus - are they False Positive?

Hi there, 

 

Lately we have seen number of blocked connection for Teams.nuspec. Virus Total report for Destination IP is shows clean. 

msb_itservices_0-1591769500924.png

 


Accepted Solutions
Highlighted
L7 Applicator

346947453 was disabled and is now removed from Antivirus 3381

View solution in original post


All Replies
Highlighted
L0 Member

We've seen a bunch of these as well from when we first started using Microsoft Teams.

Since then, we have bursts of them.  Yesterday was a bad day.  I think they are false positives as well, but I'd love to better understand why we are getting them.

Highlighted
L7 Applicator

Please open a Support case so it can be looked at in detail.

Highlighted
L1 Bithead

I have also been seeing this file across some of our customers that we monitor. We will get Virus alerts for that file that WildFire is flagging. I don't think this is a virus and is more than likely a false+. I was looking into this a little further and found out that the file is being hosted here https://chocolatey.org/packages/microsoft-teams#files. The file passes all checks on their site which you can view the Registry Snapshot by going to the following link https://gist.github.com/choco-bot/94b957a0ae5da9a075eb88dd4c890bd9. If I get some time I will download the file on my VM and run it through some checks and will update. I agree with the above comment and open a case so that Palo can take a look into this further. Have a good day! 

Highlighted
L7 Applicator

We are looking at it further to understand what is causing the continued FP detections.

All the signatures listed in the screenshot are now disabled.

Highlighted
L0 Member

still false-positives for threat id: 346399143  filename: Teams.nuspec -  Virus/Win32.WGeneric.akfdwd

Content version: Antivirus-3376-3887

Highlighted
L5 Sessionator

The signature 346399143 was disabled 06/11/2020

Highlighted
L7 Applicator

The signature is removed beginning with Antivirus version 3377-3888

Highlighted
L0 Member

Another: teams.nuspec -  Virus/Win32.WGeneric.a

signature: 346947453 (in Antivirus-3380-3891)

Filename: Teams.nuspec

 

 
Highlighted
L0 Member

Same!  We've received a bunch of those as well.

The virus 346947453(346947453) was detected at Teams.nuspec

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!