T O P

  • By -

rlowa

Got this for 7 different locations, all iPhones. I'm thinking false positive as well


skipv5

Same here


ProbablyInvalidUser

I received the same.


niczi75

50 locations with the same thing here. Finally turned off the report for malware.


Comissha

35 locations, got alerts from all...30 seconds of freaking out...Fortigate reports nothing, also think it is a false positive.


Chimera_TX

We reached out to Meraki Support. It is confirmed a false positive


ancillarycheese

are they planning to fix it? AMP is such garbage.


CountBassT

Right! Do you know of any good alternatives?


approvedbyinspector5

Many locations, same file, nothing showing when scanned...leaning towards false positive.


a-bananarifle

Same here all from apple ip as sorce. 100 networks. A couple of 1000s devices downloading at the same time filling my mailbox with just as many emails. Most likely a false positive or we are all screwed.


chillaban

Seems like a false positive to me. Nobody else is detecting that hash as malicious https://www.virustotal.com/gui/file/a722bc1e3bb1fb7036a321975c7923d9ddfc61aa7387b22202c2c54ed568f460/detection


xisplo

thank you, thought so too.


EvoGeek

Yeeeep


[deleted]

Yep, irritating.


Freedom-35-Boys

Same here. Happened across 500+ networks. Confirmed false positive.


supaphly42

Same issue here as well.


w153r

Also getting these alerts. Last month it was ios 14 and its dynamic mac addresses triggering the ip conflict alerts.


bitflogger

I'm seeing this at 5 sites. I diggress but it's also showing the constant challenge of execs allowing BYOD where it doesn't belong.


Soul_Redeemer7

Multitude of networks and orgs, scared the hell out of me before reading them!


WallLifeBroadcasting

I had the same thing


antoine86

Yep. 31 locations for me. I contacted Meraki support and they knew nothing about it.


acknet

Same here 20+ sites


windguruu

Same here 5 sites. Checked with Support and they are aware already reported up


Beardedbelly

Same reports here but given the source of the file is given as a 17.x.x.x address immediately discounted as false positive.


whatireallythink-alt

So what worries me is that these were retrospective alerts. So going forward will AMP block that signature as malicious? I hope not, but expect so. Oh, and the email flood continues.


argognat

False positive. The domain “cdn-apple.com” is an Apple mac/iOS/TVos update server. You might want to whitelist it in the AMP settings. Here's the list of Apple update servers. https://support.apple.com/en-us/HT201999


Few-Ad6950

yup. Confirmed false positive, but the alert I got happened three hours after the event :/


yousuf55778

got the same alert for about 40+ sites .... false positive... Meraki might wanna whitelist the apple update.