Malware object (with AV-Suite detection)

Prev Next

Malware-object alerts indicate that the endpoint downloaded a known malicious binary. In this case, the AV-Suite also had a match on this malware and was able to give the malware a more specific name. Malware objects are not blocked; however, subsequent requests to the same URL will be blocked.

The endpoint should be investigated for the presence of a malicious file. If the end user knowingly downloaded the file but did not execute it, the endpoint might be clean. It is possible that the file was dropped and executed without the userʼs knowledge.

If the end user ran the binary, it is likely that the endpoint is compromised, unless the binary only works on certain software versions. In this case, the endpoint should be removed from the network for additional analysis. Check local security logs and SIEM logs. You can also use the Endpoint Security (HX) server for triage investigation.