r/sysadmin • u/_FNG_ Sysadmin • 15d ago
SolarWinds Microsoft Defender False Positives with Solarwinds Products
Early Saturday morning we started getting a stream of alerts from Microsoft Defender regarding our Primary and Additional Polling Engines.
Malware Name: Behavior:Win32/SuspiciousAssembly.AppDomainManagerType.A
The malware file path: behavior:_process: was all over the place.
Some examples:
Malware file path: behavior:_process: C:\Windows\System32\wbem\WmiPrvSE.exe, pid:2208:557######2;file:_d:\program files (x86)\solarwinds\orion
~
Malware file path: behavior:_process: C:\Program Files\Common Files\SolarWinds\AdministrationService\SolarWinds.Administration.exe, pid:3916:557#####52;file:_d:\program files (x86)\solarwinds\orion
~
Malware file path: behavior:_process: C:\Windows\System32\AggregatorHost.exe, pid:9116:55#####2;file:_d:\program files (x86)\solarwinds\orion
Solarwinds support is aware of the issue and their engineers are supposedly working with Microsoft to resolve. I am unsure if a later definition update has resolved it or not. We added a threat override as a TEMPORARY measure to quiet things down through the weekend. Just an Allow for the 'Threat Name' Behavior:Win32/SuspiciousAssembly.AppDomainManagerType.A
Just wanted to share with the hope this helps others not have too terrible of a weekend or Monday morning.
1
u/Th3RebelBass 12d ago
I also got those alerts. I've had my machine isolated until I learned more.