This alert indicates that the endpoint downloaded an unknown malicious binary, and the MVX engine detected a zero-day callback.
The endpoint should be investigated for the presence of a malicious file. If the end user knowingly downloaded the file but did not execute it, the endpoint might be clean. It is possible that the file was dropped and executed without the userʼs knowledge.
If the end user ran the binary, it is likely that the endpoint is compromised, unless the binary only works on certain software versions. In this case, the endpoint should be removed from the network for additional analysis. Check local security logs and SIEM logs. You can also use the Endpoint Security (HX) server for triage investigation.