cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
J1mX1
Level 9
Report Inappropriate Content
Message 1 of 4

ATD file detection issue - Windows 10 64bit VM - Appliance Load related?

Jump to solution
We received a number of emails with an attachment containing a PDF file with malicious links. ATD scanned one of these and classified the file as Severity 'Information'. It was busy at that point in time and I can see that the Processing Time was 103 seconds with a Sandbox Replication of 90 seconds. I am assuming the sandbox process therefore did not complete? There are no details (all state 'Unverified') for the GTI URL Reputation and all other Engine Analysis engines listed on the Threat analysis Report. When I then resubmitted the file manually in User-Interactive (X-mode) the threat came back 'Very High' and I can see the the GTI Web/URL Reputation data was pulled for 17 connected sites with a final classification of 'Malware- Malicious sites', 'Engine - GTI URL Reputation'. My concern is that the original scan of this incoming attachment passed it on as OK where as this second more complete scan detected it correctly as malicious. Does this happen if the CPU load is excessive and there is a backlog of file to process? If so, is there a way of finding out how many files are not being fully analysed at such busy periods? I am not aware if there is any guidance on when a second appliance is required from a processing point of view if this could just be a sandbox image issue?
1 Solution

Accepted Solutions
hsadi1
McAfee Retired
McAfee Retired
Report Inappropriate Content
Message 3 of 4

Re: ATD file detection issue - Windows 10 64bit VM - Appliance Load related?

Jump to solution

Hi J1mX1,

Thank you for contacting us regarding the analysis issue.

We have seen in the past different results between submitting a sample manually with xmode and automatically submitted by another device. The difference is that when submitting a sample using xmode the user would interact with the sample for the ATD to detect.

Note: submitting a sample with xmode the sample is sent to Dynamic Analysis and you mentioned that the sample was detected by GTI Web/URL engine which is the static analysis.

We need the sample's complete result and the support bundle to verify if ATD did not have any issue when it scanned that sample at that specific moment.

I would advise to raise an SR with McAfee ATD Support so we can troubleshoot the issue.

Best regards, 

View solution in original post

3 Replies
J1mX1
Level 9
Report Inappropriate Content
Message 2 of 4

Re: ATD file detection issue - Windows 10 64bit VM - Appliance Load related?

Jump to solution
Any thoughts anyone?
hsadi1
McAfee Retired
McAfee Retired
Report Inappropriate Content
Message 3 of 4

Re: ATD file detection issue - Windows 10 64bit VM - Appliance Load related?

Jump to solution

Hi J1mX1,

Thank you for contacting us regarding the analysis issue.

We have seen in the past different results between submitting a sample manually with xmode and automatically submitted by another device. The difference is that when submitting a sample using xmode the user would interact with the sample for the ATD to detect.

Note: submitting a sample with xmode the sample is sent to Dynamic Analysis and you mentioned that the sample was detected by GTI Web/URL engine which is the static analysis.

We need the sample's complete result and the support bundle to verify if ATD did not have any issue when it scanned that sample at that specific moment.

I would advise to raise an SR with McAfee ATD Support so we can troubleshoot the issue.

Best regards, 

bretzeli
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 4 of 4

Re: ATD file detection issue - Windows 10 64bit VM - Appliance Load related?

Jump to solution

Yes we have seen effects where the bot did NOT do or click stuff as it should automated. It stopped right after it rated the URL as example and did not detect the rest. But you don't a sandbox for that 😉

The rating was ONLY based on IP-Reputation of the Links in the PDF as example.

But in that case i don't need the ATD Sandbox and only Mcafee Security for Exchange 8.6/Which uses the same DB for 1/100 of the price....

We had a remote session then to proof and it was fixed. It's simplya cat and mouse game but at that point some things where not working as it should and i don't pay an extra 1/10 Million just for somethjing you get free with a regular ENS Suite (Function i mean).

Greeting from Switzerland

 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community