<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Rebe1l Malware Was Not Detected By Sophos - Customer Said</title><link>https://community.sophos.com/intercept-x-endpoint/f/discussions/128723/rebe1l-malware-was-not-detected-by-sophos---customer-said</link><description>Please is there any intelligence report on Rebe1l malware that we can read on. I have a customer who has noted that Sophos Server Protection did not detect Rebe1l on a server the malware had been before Server Protection was installed.</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Rebe1l Malware Was Not Detected By Sophos - Customer Said</title><link>https://community.sophos.com/thread/472439?ContentTypeID=1</link><pubDate>Mon, 05 Jul 2021 11:31:03 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:76b87dd7-6ac6-4613-80eb-aa513740f811</guid><dc:creator>Sophos User930</dc:creator><description>&lt;p&gt;Given the info here for that hash:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.virustotal.com/gui/file/e2647be3a4726e65d7e37d2085644b292761102e2b07729887d1954f7f021b06/detection"&gt;VirusTotal&lt;/a&gt;&lt;/p&gt;
&lt;div&gt;2021-03-17 11:13:21&lt;span&gt;&amp;nbsp;&lt;/span&gt;UTC - 3 months ago&lt;/div&gt;
&lt;p&gt;Re-evaluating it now: &amp;quot;2021-07-05 11:25:55&lt;span&gt;&amp;nbsp;&lt;/span&gt;UTC -&amp;nbsp;1 minute ago&amp;quot;&lt;/p&gt;
&lt;p&gt;It still only has 3 vendors, Crowdstrike naming has it down as &amp;quot;&lt;span&gt;Win/malicious_confidence_60% (W)&amp;quot;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Where are they getting the info that the sample is malicious? The site quoted?&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Rebe1l Malware Was Not Detected By Sophos - Customer Said</title><link>https://community.sophos.com/thread/472438?ContentTypeID=1</link><pubDate>Mon, 05 Jul 2021 10:47:53 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:20363688-c077-4042-b24f-0624adb7ca75</guid><dc:creator>James Olorunosebi</dc:creator><description>&lt;p&gt;Hello GlenSen,&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Customer is unable to find the file anymore, but says he has the hash. Would this information suffice? It is publicly accessible as well on this link:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://threatinfo.net/files/rebe1l.exe-d841ab02340b04b05a6e665ce7f78975"&gt;threatinfo.net/.../rebe1l.exe-d841ab02340b04b05a6e665ce7f78975&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Rebe1l Malware Was Not Detected By Sophos - Customer Said</title><link>https://community.sophos.com/thread/472387?ContentTypeID=1</link><pubDate>Mon, 05 Jul 2021 00:27:07 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7c928c72-2db3-45f9-b734-207c1e32b712</guid><dc:creator>GlennSen</dc:creator><description>&lt;p&gt;Hi There,&lt;/p&gt;
&lt;p&gt;Thank you for reaching us,&amp;nbsp;can you confirm if the customer uses the recommended settings from Sophos which being described &lt;a href="https://support.sophos.com/support/s/article/KB-000038565?language=en_US"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Also, do you still have the sample for the said malware? Can you submit the said sample through our sample submission portal in order for our labs&amp;#39; team to check and validate the said sample? You may follow this &lt;a href="https://support.sophos.com/support/s/article/KB-000033301?language=en_US"&gt;KB article&lt;/a&gt; on how to submit a sample.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>