This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

PUA detected: 'SpiGot'

Hi

We have received multiple PUA's on 100 to 150 machines. The detected files are basically java script examples : after.js and background.js

please find the example : PUA detected: 'SpiGot' at 'C:\Users\k113899\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lbpcfgdgiemlcaggjhjcinhblflmgdlj\2.2_0\after.js'

 

These detection's came in off business hours and today we might see more users with the same alert. 

 

So my question is did this alert triggered from Sophos end ?

 



This thread was automatically locked due to age.
Parents
  • Hi Amit Thakur,

    Could you help me with the Sophos product that you are using?

    As already mentioned, there was a new definition update pushed on 29th Sep for a similar/same file (You can verify the file from the VirusTotal link). This new definition classifies the file as PUA, which could have resulted in multiple detections over the endpoints. Sophos Clean should have been able to clear it

    Regards,

    Gowtham Mani
    Community Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

  • Hi ,

     

    We are using 

    Endpoint Advanced Protection

    Intercept X

     

    when checked manually the file was not their on users machine. Could you provide more detailed info on the new definition released and for which product ?

     

  • Hello Amit Thakur,

    [I'm not Sophos]
    more detailed info
    what kind of details would you need? As it is a PUA detection it has been made by the Endpoint component. PUA detections aim to identify a certain application by specific distinct characteristics, details would be too technical to be of use. The same definitions are used for all products.

    not there on users machine
    what happened after the detection depends on the type of scan. PUAs can be removed with scheduled scans, On-Access scanning only blocks them. The machine's Anti-Virus log (SAV.txt) should tell what action has been performed.

    Christian

Reply
  • Hello Amit Thakur,

    [I'm not Sophos]
    more detailed info
    what kind of details would you need? As it is a PUA detection it has been made by the Endpoint component. PUA detections aim to identify a certain application by specific distinct characteristics, details would be too technical to be of use. The same definitions are used for all products.

    not there on users machine
    what happened after the detection depends on the type of scan. PUAs can be removed with scheduled scans, On-Access scanning only blocks them. The machine's Anti-Virus log (SAV.txt) should tell what action has been performed.

    Christian

Children
No Data