False-Positive , Office365 Sharepoint marked as Phishing in Content-Filter

Options

Currently the Office365 Sharepoint Node dual-spo-0003.spo-msedge.net (Switzerland) is being marked as phishing.

This stopped one of our customer of over 40 People to access their Sharepoint Data since early morning.

Other SPO Nodes are not being marked. This probably happened, because somebody tried to use the Office365 Sharepoint plattform to deploy some kind of malware/virus ect…

Please investigate this.

Sincerely

Fabian Zünd

SI-Solutions GmbH

All Replies

  • LukeCC
    LukeCC Posts: 3
    First Comment
    Options

    same at one of our customers that are using ATP800: they were not able to use their sharepoint 365 resources

  • KS1983
    KS1983 Posts: 2
    First Comment
    Options

    same with ATP200, do you have a solution? whitelisting, disabling phishing category etc does not change anything.. Our custormers are still not able to connect to their office365 filedata

  • morezh
    morezh Posts: 10  Freshman Member
    10 Comments Friend Collector Zyxel Certified Network Engineer Level 1 - Security
    Options

    Same error on various ATP 200s. Bypass *.sharepoint.com in the URL and DNS Threat Filter exclude and then clear the cache via the Web CLI of the firewall. After that, access works again. (This is only an emergency solution!)

  • leop800
    leop800 Posts: 1  Freshman Member
    First Anniversary First Comment Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Security
    Options

    Hi, how can I clear the cache?

  • LukeCC
    LukeCC Posts: 3
    First Comment
    Options

    be careful whitelisting all sharepoint.com, it would be safer to whitelist only your own "customername".sharepoint.com cause there are a lot of phishing campaigns that run with compromised sharepoint.com link inside

  • morezh
    morezh Posts: 10  Freshman Member
    10 Comments Friend Collector Zyxel Certified Network Engineer Level 1 - Security
    Options

    Login via Console
    Router# configure terminal
    Router#(config) ip dns server cache-flush

  • Zyxel_James
    Zyxel_James Posts: 626  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hello @SI_Solutions

    dual-spo-0003.spo-msedge.net has been recategorized as Content Server with Minimal Risk. Please check again, thank you.

  • Zyxel_James
    Zyxel_James Posts: 626  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    edited May 2023
    Options

    Hello @LukeCC @KS1983 @morezh @leop800

    Is it also categorized as phishing? we receive several reports like this but some of them are recovered and recategorized as Interactive Web Applications.
    Please check if the issue persists, if so, please provide the SharePoint URL and the blocked log, thank you.

  • SI_Solutions
    SI_Solutions Posts: 2
    First Comment
    edited May 2023
    Options

    We added an exception for customername.sharepoint.com as well as dual-spo-0003.spo-msedge.net to the Content-Filter ⇒ Trusted Websites, DNS-Content-Filter ⇒ Allow List, Reputation Filter ⇒ Allow List (IP of the DNS Entry), DNS-Thread Filter ⇒ Allow-List, and URL-Threat Filter ⇒ Allow List

    After this we rebootet the ATP500 as well as our internal DNS Server, becuase the DNS Entry was still pointing at the wrong ip/ the Zyxel Warning Server instead of the normal ip.

    The IP-Reputation Filter still marked the IP as malicious so i updated the Signatures by hand this early morning. (1.0.0.20230515.0)

    Now the URL dual-spo-0003.spo-msedge.net is identified as:

    By Content-Filter: Content-Server
    HTTPS: Domain Filter: Content-Server
    URL Threat Filter: Not Found
    IP-Reputation: Neutral
    DNS-Threat Filter: Not Found

    To me it looks resolved with the newest Signatures.

  • Zyxel_James
    Zyxel_James Posts: 626  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    @SI_Solutions , thanks for your feedback.

Security Highlight