Jump to content

Malware.AI.3884307183


AlexLeadingEdge

Recommended Posts

The location is the SolarWinds Patch Management cache. I don't know what this file is, some sort of update patch for one of our software packages I assume.

Two vendors have flagged it in VirusTotal. CrowdStrike gives it a 60% confidence that it is a virus.

https://www.virustotal.com/gui/file/1519a153cd3b93c1e56ad5f6ffc98195e2c68e963a14a74558b7b4c0adbf4e55/detection

 

C:\PROGRAMDATA\MSPPLATFORM\FILECACHESERVICEAGENT\CACHE\A3B68742-F6D4-4DF1-B217-B7EC66B4C314.1.EXE

 

File attached with password 'infected'

a3b68742-f6d4-4df1-b217-b7ec66b4c314.1.zip

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.