Sep 06 2024 08:42 AM
Hello,
We are running Defender in a GCC High environment and recently ran into an issue where a new custom SHA-256 hash indicator was triggering/alerting for hundreds of UNIQUE files. Searching for the SHA-256 value in "Advanced Hunting" returns thousands of unique files (different file names/types) but shows the same file size for all of them (which is not accurate). We discovered that the hash value is actually pointing to the Zone.Identifier stream data on these files.
Any idea what would cause the Zone.Identifier data to be hashed while the content of the associated file is ignored?
Thank you.
Lucas
Sep 09 2024 06:19 AM
Sep 09 2024 08:00 AM
Sep 10 2024 05:07 AM