Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Cb Defense: Why does the 'System' Application hash appear as '000000000000000000000000000000000000000' in the Console

Cb Defense: Why does the 'System' Application hash appear as '000000000000000000000000000000000000000' in the Console

Environment

  • Cb Defense Console (All Versions)

Question

In the Management Console, there is a 'System' application which shows up hash value of '000000000000000000000000000000000000000', why is this?

Answer

There is no system.exe file (as indicated by the Application: System, in these events), so there is no file to hash.

Our Sensor Service is not able to figure out the path for "system", so leaves the hash as 0x00000000, which displays in the Console as '0000000000000000000000000000000000000000000000000000000000000000'

Additional Notes

Although this may look strange, this has no effect on any associated event

Related Content

Screenshot from Console showing an example event:

Internal Reference: EA-12353

Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-07-2018
Views:
373
Contributors