Forum Discussion

tpawlina's avatar
tpawlina
Copper Contributor
Apr 29, 2021

Please fine tune alerting - CLOUD APP SECURITY

Description
The user XXXXXXXX@XXX.com) manipulated 61 files with multiple extensions ending with the uncommon extension pobierz. This is an unusual number of file manipulations and is indicative of a potential ransomware attack.


This is not a ransomware extension.
It's a FP.

pobierz (Polish word) means download (english)

Please tune it out from alerting immediatly.

No RepliesBe the first to reply