Forum Discussion

Scott Preston's avatar
Scott Preston
Iron Contributor
Jun 18, 2019

ATP False Positives

We have alerts set up to detect outbound malware and recently we are receiving a lot of alerts regarding attachments being marked by MS as a threat.

 

The attachments are ATT files and all of the emails marked have the following hash file

961E95EB029767015671BA8562467FCE6C27899CF58C153CFEC1403B10B817B0

 

On checking this out on places like virustotal it is deemed clean.

 

I've opened a support case to Microsoft and they have told me that they must be malicious or else ATP wouldn't flag this.

 

I'm pretty sure this is a false positive but no idea how to proceed as support tell me there is no way to submit these as false positives.

 

I know there was a recent incident regarding incorrectly quarantined messages (
EX182195 - Remnant quarantined messages)


I'm wondering if this is fallout from this incident still hanging around.

 

Any advice

 

Thanks

7 Replies

  • m2021acct's avatar
    m2021acct
    Copper Contributor

    +1 here.

     

    Same ordeal here. Multiple detections and warnings.

    Could this please be looked into?

     

    Thank You

  • Apart from reporting the messages to Microsoft, there's hardly anything you can do. 

    • Scott Preston's avatar
      Scott Preston
      Iron Contributor

      VasilMichev Thanks for the prompt reply.

       

      Reported it to Microsoft and as mentioned they said it must be malware. I've taken the file from one email and it checks out clean on many engines. 

       

      Microsoft provided me a link to a submission site for Windows Defender and this has come back clean also and they have said that it has been previously removed as a threat from their database. 

      Not sure if ATP or online services use the same engine for this type of threat but now Microsoft are telling me to wait 24 hours and check the behaviour. Not filling me with confidence I'm afraid.

      • Ezra Pound's avatar
        Ezra Pound
        Copper Contributor

        Scott Preston Did you ever get any where with this? We are experiencing the exact same issue/same hash and its getting flagged about 60+ times a day across various users/mailboxes.