We are seeing lot of Teams.nuspec as virus - are they False Positive?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

We are seeing lot of Teams.nuspec as virus - are they False Positive?

L0 Member

Hi there, 

 

Lately we have seen number of blocked connection for Teams.nuspec. Virus Total report for Destination IP is shows clean. 

msb_itservices_0-1591769500924.png

 

1 accepted solution

Accepted Solutions

346947453 was disabled and is now removed from Antivirus 3381

View solution in original post

12 REPLIES 12

L0 Member

We've seen a bunch of these as well from when we first started using Microsoft Teams.

Since then, we have bursts of them.  Yesterday was a bad day.  I think they are false positives as well, but I'd love to better understand why we are getting them.

Please open a Support case so it can be looked at in detail.

L1 Bithead

I have also been seeing this file across some of our customers that we monitor. We will get Virus alerts for that file that WildFire is flagging. I don't think this is a virus and is more than likely a false+. I was looking into this a little further and found out that the file is being hosted here https://chocolatey.org/packages/microsoft-teams#files. The file passes all checks on their site which you can view the Registry Snapshot by going to the following link https://gist.github.com/choco-bot/94b957a0ae5da9a075eb88dd4c890bd9. If I get some time I will download the file on my VM and run it through some checks and will update. I agree with the above comment and open a case so that Palo can take a look into this further. Have a good day! 

We are looking at it further to understand what is causing the continued FP detections.

All the signatures listed in the screenshot are now disabled.

still false-positives for threat id: 346399143  filename: Teams.nuspec -  Virus/Win32.WGeneric.akfdwd

Content version: Antivirus-3376-3887

The signature 346399143 was disabled 06/11/2020

The signature is removed beginning with Antivirus version 3377-3888

Another: teams.nuspec -  Virus/Win32.WGeneric.a

signature: 346947453 (in Antivirus-3380-3891)

Filename: Teams.nuspec

 

 

Same!  We've received a bunch of those as well.

The virus 346947453(346947453) was detected at Teams.nuspec

346947453 was disabled and is now removed from Antivirus 3381

And it seems to be back again - Threat ID #356771745 Virus Teams.nuspec detected via an Antivirus profile.Excluded it and raising a note with PAN.

356771745 was disabled and will be removed from tomorrow's release of the Antivirus signature package.

  • 1 accepted solution
  • 11132 Views
  • 12 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!