This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Malware false positive from iOS devices

I've noticed several of these entries in the logs as malware:

2018-05-08 08:12:02Malwaremessageid="08001" log_type="Anti-Virus" log_component="HTTP" log_subtype="Virus" status="" fw_rule_id="5" user="" web_policy_id="12" policy_name="" virus="" url="eventtracking.hubapi.com/.../*[deleted]" domain="eventtracking.hubapi.com" src_ip="172.16.16.50" src_country="R1" dst_ip="104.17.202.204" dst_country="USA" protocol="TCP" src_port="52636" dst_port="80" bytes_sent="632" bytes_received="729" user_agent="Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E302" status_code="500"

It appears to be only coming from my iOS devices. I'm fairly confident it's not actually malware but I'm curious as to what is causing Sophos XG to flag it as malware. Anyone else seeing this or know what's causing it? I can't seem to isolate it to a certain app or website either.



This thread was automatically locked due to age.
Parents Reply Children
  • I don't mean to take over Shred's post, but since I am experiencing the same  thing I will reply as well:

     

    Here's the Sophos pattern update:

    Sophos AV
    1.0.12632
    -
    08:05:27, May 25 2018
    Success

     

    Looked in logs and Im still getting them, so here's one from this morning:

    messageid="08001"
    log_type="Anti-Virus"
    log_component="HTTP"
    log_subtype="Virus"
    status=""
    fw_rule_id="5"
    user=""
    web_policy_id="4"
    policy_name=""
    virus=""
    url="eventtracking.hubapi.com/.../blahblahblah--stuff deleted ---"
    domain="eventtracking.hubapi.com"
    src_ip="192.168.X.130"
    src_country="R1"
    dst_ip="104.17.200.204"
    dst_country="USA"
    protocol="TCP"
    src_port="50822"
    dst_port="80"
    bytes_sent="686"
    bytes_received="602"
    user_agent="Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
    status_code="500"