# Kibana 8.17.3 – Malware Detection of security\_labs Knowledge Base File (TROJ\_FRS.VSNTIA26)

**URL:** <https://discuss.elastic.co/t/kibana-8-17-3-malware-detection-of-security-labs-knowledge-base-file-troj-frs-vsntia26/390482>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [September 16, 2026, 10:21pm UTC](https://discuss.elastic.co/t/kibana-8-17-3-malware-detection-of-security-labs-knowledge-base-file-troj-frs-vsntia26/390482 "2026-09-16T22:21:06Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![shiva3](https://avatars.discourse-cdn.com/v4/letter/s/f1d935/32.png) [@shiva3](https://discuss.elastic.co/u/shiva3)\
**Post date:** [September 16, 2026, 10:21pm UTC](https://discuss.elastic.co/t/kibana-8-17-3-malware-detection-of-security-labs-knowledge-base-file-troj-frs-vsntia26/390482/1 "2026-09-16T22:21:06Z")

</div>

**Hello Elastic Team,**

We are investigating a security alert involving the **Kibana 8.17.3 Docker image** deployed in our OpenShift environment.

Our endpoint security product detected the following file as:

**Detection:** `TROJ_FRS.VSNTIA26`  
**Action:** Deleted

```auto
/usr/share/kibana/node_modules/@kbn/elastic-assistant-plugin/server/knowledge_base/security_labs/siestagraph_new_implant_uncovered_in_asean_member_foreign_ministry.md

```

The detection occurred on **two separate servers** , and the reported file path was under the Kibana container overlay filesystem.

### **Kibana Image**

The image deployed in our environment is:

```auto
s4d1plrga01.ocp-prd-s4d1-01.sbilife.co.in:8443/kibana/kibana:8.17.3

```

Image ID:

```auto
sha256:1800828c430b4974ffe0d61380bf235441140c6119ebaaba05daec5219bf407d

```

### **Detection Details**

**Server 1**

```auto
Hostname: S4D2RLRGA01
IP: 172.19.13.120
Detection: 14-Sep-2026 04:27:58

```

**Server 2**

```auto
Hostname: S4D1LBSA01
IP: 172.17.163.120
Detection: 14-Sep-2026 02:52:40

```

Both detections reported the same filename and the same container overlay ID:

```auto
a20b2187cd48a1efb5faaf415d5bb55ed41cd82d4ef90097f3f50927f0903219

```

The file has subsequently been deleted by the security product and is no longer present at the reported path.

### **Request for Elastic Confirmation**

Could someone from the Kibana/Elastic Security team please confirm:

1. Is `siestagraph_new_implant_uncovered_in_asean_member_foreign_ministry.md` **legitimate content shipped with Kibana 8.17.3**?

2. Is the following directory expected in the official Kibana distribution?

```auto
@kbn/elastic-assistant-plugin/server/knowledge_base/security_labs/

```

1. Is this particular Markdown file part of the **Elastic Assistant / Security Labs knowledge base**?

2. If it is legitimate, why might an endpoint security product identify this file as `TROJ_FRS.VSNTIA26`?

3. Is this a **known false positive or known detection** associated with Kibana 8.17.3?

4. Can you provide an official source/repository/release artifact that confirms the file is part of the Kibana 8.17.3 distribution?

5. Can you confirm whether the file exists in the official Kibana 8.17.3 image corresponding to the image digest above?

6. If the file is **not** expected in the official Kibana 8.17.3 image, are there any known issues that could result in this file being introduced into the container?

### **Investigation Objective**

Our security team needs to determine whether this detection represents:

- legitimate Kibana application content,

- a false-positive malware detection,

- content originating from the official Kibana image, or

- an unexpected modification/injection into the container.

Since the same file was detected on two separate servers, we would particularly appreciate confirmation of the file's **origin and authenticity**.

Any official Elastic documentation, GitHub source reference, release information, or other authoritative evidence would be helpful for our security investigation and audit justification.

**Thank you for your assistance.**
