Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

During upgrade to XGS 19.5 firmware, got more than 70 email alerts for HTTP virus detected

While upgrading the firmware on my HA stack of sophos XGS 3100, I got more than 70 email alerts for the HTTP virus detected Alert ID: 8001 with the messages below repeatedly:

Malware 'Unscannable' was detected and blocked in a download from crl4.digicert.com

Malware 'Unscannable' was detected and blocked in a download from www.msftconnecttest.com

Malware 'Unscannable' was detected and blocked in a download from ocsp.digicert.com

Malware 'Unscannable' was detected and blocked in a download from crl3.digicert.com

Malware 'Unscannable' was detected and blocked in a download from crl.comodoca.com

Malware 'Unscannable' was detected and blocked in a download from ocsp.netsolssl.com

Malware 'Unscannable' was detected and blocked in a download from ocsp.pki.goog

After the upgrade completed, the email alerts stopped.

Any ideas why this happened or what is happening?



This thread was automatically locked due to age.
Parents
  • Hello there,

    Thank you for contacting the Sophos Community.

    Do you recall receiving these emails in the past at some point? It might be that some of these alerts might have been stuck in one of the appliances, and when the upgrade was happening, the worker was finally able to send them out. 

    However, I recommend you create a case with support and request an RCA.

    Let us know the Case ID once you have it, and mention the time of the upgrade and share the Access ID.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Reply
  • Hello there,

    Thank you for contacting the Sophos Community.

    Do you recall receiving these emails in the past at some point? It might be that some of these alerts might have been stuck in one of the appliances, and when the upgrade was happening, the worker was finally able to send them out. 

    However, I recommend you create a case with support and request an RCA.

    Let us know the Case ID once you have it, and mention the time of the upgrade and share the Access ID.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Children