This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Malware false positive from iOS devices

I've noticed several of these entries in the logs as malware:

2018-05-08 08:12:02Malwaremessageid="08001" log_type="Anti-Virus" log_component="HTTP" log_subtype="Virus" status="" fw_rule_id="5" user="" web_policy_id="12" policy_name="" virus="" url="eventtracking.hubapi.com/.../*[deleted]" domain="eventtracking.hubapi.com" src_ip="172.16.16.50" src_country="R1" dst_ip="104.17.202.204" dst_country="USA" protocol="TCP" src_port="52636" dst_port="80" bytes_sent="632" bytes_received="729" user_agent="Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E302" status_code="500"

It appears to be only coming from my iOS devices. I'm fairly confident it's not actually malware but I'm curious as to what is causing Sophos XG to flag it as malware. Anyone else seeing this or know what's causing it? I can't seem to isolate it to a certain app or website either.



This thread was automatically locked due to age.
Parents Reply
  • sachingurung said:

    Hi,

    Changing the AV Engine will let us know if we need to update something on the Sophos database and Scanning mode is how the Engine will scan the content for Malware. You can find more information here, Sophos XG Firewall: What is Batch Mode and Real Mode in Malware Scanning?.

    Thanks,

     
    Ah, okay - makes sense. 
     
    Well, I haven't seen anymore of these false positives in my firewall logs for 15 days now, so I'm fairly confident it's not occurring with the Avira engine and Batch Mode. I can continue testing this for longer if needed but I'd like to at least switch back to Real-time scanning mode as soon as I can as the batch mode becomes problematic with large downloads.
Children
No Data