<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SANDSTORM marks sucpicous files as clean</title><link>https://community.sophos.com/utm-firewall/f/mail-protection-smtp-pop3-antispam-and-antivirus/126935/sandstorm-marks-sucpicous-files-as-clean</link><description>Hi, 
 we have a problem at some firewalls, sandstorm is marking files as clean, but report sees bad behaviour. 
 Do you have such reports? 
 Thanks 
 may</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: SANDSTORM marks sucpicous files as clean</title><link>https://community.sophos.com/thread/464979?ContentTypeID=1</link><pubDate>Thu, 01 Apr 2021 14:27:25 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:faf53863-3431-4061-987e-d6a0c6eae123</guid><dc:creator>maygyver</dc:creator><description>&lt;p&gt;Firmware 9.705-3.&lt;/p&gt;
&lt;p&gt;SMTP Sandstorm is active with&amp;nbsp; Frankfurt Datacenter, no excluded mime types.&lt;/p&gt;
&lt;p&gt;I have several zips, with xlsm files inside. Sandstorm&amp;nbsp;analysis:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A process was injected into by writing directly to an API address&lt;/li&gt;
&lt;li&gt;API indication that Office intents to perform a HTTP download&lt;/li&gt;
&lt;li&gt;Office writes directly to a memory region&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;But it is marked as Clean.&lt;/p&gt;
&lt;p&gt;log:&lt;/p&gt;
&lt;p&gt;sandboxd-2021-03-23.log:2021:03:23-13:58:02 gw-1 sandboxd[12870]: h=- u=&amp;quot;112.204.89.132&amp;quot; s=200 X=- t=1616503969 T=313000000 Ts=313 act=1 cat=&amp;quot;-&amp;quot; app=&amp;quot;-&amp;quot; rsn=- threat=&amp;quot;-&amp;quot; type=&amp;quot;-&amp;quot; ctype=&amp;quot;-&amp;quot; sav-ev=- sav-dv=- uri-dv=- cache=- in=- out=73372 meth=GET ref=&amp;quot;-&amp;quot; ua=&amp;quot;-&amp;quot; req=&amp;quot;GET xxx HTTP/1.1&amp;quot; dom=&amp;quot;wkrajcik@grupoedelsur.com&amp;quot; filetype=&amp;quot;application/octet-stream&amp;quot; rule=&amp;quot;-&amp;quot; filesize=73372 axtime=- fttime=- scantime=- src_cat=&amp;quot;-&amp;quot; labs_cat=&amp;quot;-&amp;quot; dcat_prox=&amp;quot;-&amp;quot; target_ip=&amp;quot;-&amp;quot; labs_rule_id=&amp;quot;-&amp;quot; reqtime=- adtime=- ftbypass=- os=- authn=- auth_by=- dnstime=- quotatime=- sandbox=4&lt;br /&gt;sandboxd-2021-03-23.log:2021:03:23-14:10:02 gw-1 sandboxd[12870]: h=- u=&amp;quot;112.204.89.132&amp;quot; s=200 X=- t=1616504600 T=402000000 Ts=402 act=1 cat=&amp;quot;-&amp;quot; app=&amp;quot;-&amp;quot; rsn=- threat=&amp;quot;-&amp;quot; type=&amp;quot;-&amp;quot; ctype=&amp;quot;-&amp;quot; sav-ev=- sav-dv=- uri-dv=- cache=- in=- out=73362 meth=GET ref=&amp;quot;-&amp;quot; ua=&amp;quot;-&amp;quot; req=&amp;quot;GET xxx HTTP/1.1&amp;quot; dom=&amp;quot;wkrajcik@grupoedelsur.com&amp;quot; filetype=&amp;quot;application/octet-stream&amp;quot; rule=&amp;quot;-&amp;quot; filesize=73362 axtime=- fttime=- scantime=- src_cat=&amp;quot;-&amp;quot; labs_cat=&amp;quot;-&amp;quot; dcat_prox=&amp;quot;-&amp;quot; target_ip=&amp;quot;-&amp;quot; labs_rule_id=&amp;quot;-&amp;quot; reqtime=- adtime=- ftbypass=- os=- authn=- auth_by=- dnstime=- quotatime=- sandbox=4&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;may&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: SANDSTORM marks sucpicous files as clean</title><link>https://community.sophos.com/thread/464806?ContentTypeID=1</link><pubDate>Tue, 30 Mar 2021 15:12:27 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:fd0b0031-9ad0-47e6-87b1-c9ff27274732</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/maygyver"&gt;maygyver&lt;/a&gt;,&lt;/p&gt;
&lt;p&gt;Thanks for reaching out to the Community!&lt;/p&gt;
&lt;p&gt;What is the firmware version on your firewall? Could you please provide more detail about the sandstorm configuration and sandboxd.log?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>