Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

false positives #61

Closed
Q7ak5 opened this issue Feb 17, 2019 · 1 comment
Closed

false positives #61

Q7ak5 opened this issue Feb 17, 2019 · 1 comment

Comments

@Q7ak5
Copy link

Q7ak5 commented Feb 17, 2019

In Spark two files will trigger some alerts:

11a1a8e958b8334207ada4f8db79a82a,C:\WINDOWS\softwaredistribution.bak\Download\2ccde37d195aba85099ad54774cf0fe2\amd64_Microsoft-Windows-Client-Features-PackageAMD6410.0.17763.1\amd64_microsoft-windows-synchost_31bf3856ad364e35_10.0.17763.1_none_5a46f6fe54bbd2df\synchost.exe,90  
b2716691d5f75f1f2a965923e180ce36,C:\WINDOWS\softwaredistribution.bak\Download\2ccde37d195aba85099ad54774cf0fe2\amd64_Microsoft-Windows-Client-Features-WOW64-PackageAMD6410.0.17763.1\wow64_microsoft-windows-synchost_31bf3856ad364e35_10.0.17763.1_none_649ba150891c94da\synchost.exe,90

Both files were sent to lab, no malware was found. Also ok, according Virus Total scans, countercheck it by hashes. In loki, those files trigger no alert.

@Neo23x0
Copy link
Owner

Neo23x0 commented Oct 25, 2022

Not enough info to do something with that feedback. No hash, no rule name. Closing.

@Neo23x0 Neo23x0 closed this as completed Oct 25, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants