Start a Conversation

Solved!

Go to Solution

2313

July 25th, 2022 10:00

Two Samsung SSD Firmware Updates from Dell.com Flagged as Malicious

Hello Dell Community,

We came across two different alerts for two different Samsung SSD firmware updates from Dell.com and the child process is flagged as malicious. Parent process is flagged safe. I uploaded both files to our sandbox analysis tool and both reported no specific threat.

Can you assist with verifying if these files are malicious or not?

https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=hvpc3 https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=G4GWG

https://www.hybrid-analysis.com/sample/528ead5c727118347683b59a74d99bf6309cb6c2c955ed5c7cb1f1d75006dbb1

no specific threat

https://www.hybrid-analysis.com/sample/c43da3d88be4cb35670d246302349096e02ec628a92765f04d3f429b4f7a766a

no specific threat

https://www.hybrid-analysis.com/sample/e016ee21712ce6c3f1aaeb44df03b426a5e5c11094dd019e110a105c5c779792

malicious

https://www.virustotal.com/gui/file/e016ee21712ce6c3f1aaeb44df03b426a5e5c11094dd019e110a105c5c779792/detection

5 security vendors and no sandboxes flagged this file as malicious

Thank you.

1 Message

July 27th, 2022 04:00

Stumbled over the same VT detection, luckily Crowdstrike flagged them as false positive

No Events found!

Top