Forum Discussion
ATP False Positives
Apart from reporting the messages to Microsoft, there's hardly anything you can do.
- Scott PrestonJun 19, 2019Iron Contributor
VasilMichev Thanks for the prompt reply.
Reported it to Microsoft and as mentioned they said it must be malware. I've taken the file from one email and it checks out clean on many engines.
Microsoft provided me a link to a submission site for Windows Defender and this has come back clean also and they have said that it has been previously removed as a threat from their database.
Not sure if ATP or online services use the same engine for this type of threat but now Microsoft are telling me to wait 24 hours and check the behaviour. Not filling me with confidence I'm afraid.
- Ezra PoundJul 11, 2019Copper Contributor
Scott Preston Did you ever get any where with this? We are experiencing the exact same issue/same hash and its getting flagged about 60+ times a day across various users/mailboxes.
- Scott PrestonJul 11, 2019Iron Contributor
Ezra Pound We are still experiencing this.
We are on our 23rd day of support calls with Microsoft regarding this. Initially support suggested it is actually infected files, which we had checked out a few samples.
I've had to explain to Microsoft how the ATT00002.HTM files are generated and have replicated the issues several times.
It appears to happen when emails are sent to users which contain attachments and inline images such as an Email signature in Outlook. All the files being flagged are attached when someone forwards the emails from and apple client.
Microsoft Support have recently indicated that it is only our tenant this is happening with but clearly not the case.
A lot of the time with Microsoft support has been wasted explaining how the flagged files are actually being generated rather than actually determining why the files are being flagged as Malware in our alerts.
I suggest you open a support case with Microsoft.