This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Events Malware detections - mookie1.com - CDN - Adware - Reference ID 48326256

My organization has been getting a ton of Web event alerts today from any website with CDN ad delivery embedded content.  It began with a CDN-akamai content referral and has continued all morning via a mookie1.com URL.  The Sophos reference number attached to the Threat detection is #48326256 - Mal/HTMLGen-A

Can anyone confirm if the Sophos AV definitions were updated today and are aggressively identifying this Ad content as malware?  It's being blocked by our Enterprise Console installation but continues to be detected anytime you go back to any embedded ad content websites. 

At this rate, my web event logs Organization wide are going to be exploding by the end of the week. 

Any feedback is appreciated.  I'm also going to report it to Sophos support.  I'll update here if I get further information from them.

:57585


This thread was automatically locked due to age.
Parents
  • Thanks guys.  Yes, after the initial flurry of alerting and flags from the Sophos detection engine, it slowed and ultimately stopped.  I presume the threat definitions were updated to exclude or adjust the filtering for this content, as I know we didn't change our behavior or our screening procedures but we stopped receiving the alerts. 

    :57627
Reply
  • Thanks guys.  Yes, after the initial flurry of alerting and flags from the Sophos detection engine, it slowed and ultimately stopped.  I presume the threat definitions were updated to exclude or adjust the filtering for this content, as I know we didn't change our behavior or our screening procedures but we stopped receiving the alerts. 

    :57627
Children
No Data