cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Detection of W97M/Downloader.cyv from Machine running VSE

Recently we have seen a rash of this variant W97M/Downloader.cyv of this known threat.

Just wondering about this variant of the W97M/Downloader Trojan. We have the document McAfee Labs Threat Advisory - W97MDownloader and X97MDownloader.pdf

It is very thorough. I was wondering if there was updated information that could pertain to any additional steps to take. For example new sites to block, new rules to add or any other data that could help in making sure we are safe from this attack.

 

Stewart
6 Replies
jsam
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 7

Re: Detection of W97M/Downloader.cyv from Machine running VSE

Hi, can you please provide the chksum hash(es) for this variant from the VSE OAS log  / ePO threat events?   

Re: Detection of W97M/Downloader.cyv from Machine running VSE

Is this what you are looking for?

5a8928895bbbdfef7fdec9bc93a7c72b

Stewart
jsam
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 7

Re: Detection of W97M/Downloader.cyv from Machine running VSE

Hi, thanks, but not finding that hash. This .cyv detection name covers a number of hashes so  can you please paste the detail from the log / ePO so we can confirm if it was via dat / ed / tie / gti  ? 

Re: Detection of W97M/Downloader.cyv from Machine running VSE

If you are looking for OAS logs from the machine, we have already wiped and re-imaged it.

Is there a way to see that data from ePO?

Stewart
jsam
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 6 of 7

Re: Detection of W97M/Downloader.cyv from Machine running VSE

jsam
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 7 of 7

Re: Detection of W97M/Downloader.cyv from Machine running VSE

If you are seeing a number of detection`s for the same variant , may be worth running a report as per : How to build a Threat Source report for VirusScan Enterprise in ePolicy Orchestrator . Technical Articles ID: KB81336

 
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community