Recently we have seen a rash of this variant W97M/Downloader.cyv of this known threat.
Just wondering about this variant of the W97M/Downloader Trojan. We have the document McAfee Labs Threat Advisory - W97MDownloader and X97MDownloader.pdf
It is very thorough. I was wondering if there was updated information that could pertain to any additional steps to take. For example new sites to block, new rules to add or any other data that could help in making sure we are safe from this attack.
Hi, can you please provide the chksum hash(es) for this variant from the VSE OAS log / ePO threat events?
Is this what you are looking for?
5a8928895bbbdfef7fdec9bc93a7c72b
Hi, thanks, but not finding that hash. This .cyv detection name covers a number of hashes so can you please paste the detail from the log / ePO so we can confirm if it was via dat / ed / tie / gti ?
If you are looking for OAS logs from the machine, we have already wiped and re-imaged it.
Is there a way to see that data from ePO?
You should have some detail in the ePO threat events . https://docs.mcafee.com/bundle/epolicy-orchestrator-5.9.x-interface-reference-guide/page/GUID-419B13...
If you are seeing a number of detection`s for the same variant , may be worth running a report as per : How to build a Threat Source report for VirusScan Enterprise in ePolicy Orchestrator . Technical Articles ID: KB81336
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA