# 'ScrInject' malware was detected

**URL:** <https://discuss.elastic.co/t/scrinject-malware-was-detected/370156>\
**Category:** Elastic Security\
**Created:** [November 7, 2024, 8:14am UTC](https://discuss.elastic.co/t/scrinject-malware-was-detected/370156 "2024-11-07T08:14:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![GKre](https://avatars.discourse-cdn.com/v4/letter/g/ecae2f/32.png) [@GKre](https://discuss.elastic.co/u/GKre)\
**Post date:** [November 7, 2024, 8:14am UTC](https://discuss.elastic.co/t/scrinject-malware-was-detected/370156/1 "2024-11-07T08:14:18Z")

</div>

I am receiving alerts in MS-Defender type " 'ScrInject' malware was detected".  
The context is elastic-endpoint.exe and some .ndjson files like  
elastic-agent-event-log-20241103-156.ndjson  
I made an exclusion as i think this is a false positive.  
But i only "think it is" and do not know 😉  
Is this a known issue and what is causing this? As far as i understand the alert it is about "injecting" malicious code. I'd not expect this in event log data?

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [November 7, 2024, 2:47pm UTC](https://discuss.elastic.co/t/scrinject-malware-was-detected/370156/2 "2024-11-07T14:47:57Z")

</div>

I don't know what would cause this. `elastic-endpoint.exe` doesn't write to that file but `elastic-agent.exe` would, I assume that's what happened?

It would help understand what happened if you shared the MS-Defender alert and a copy of the ndjson file (or at least logs from when the alert happened). You can DM me those things.

---

<div class="post-metadata">

**Author:** ![GKre](https://avatars.discourse-cdn.com/v4/letter/g/ecae2f/32.png) [@GKre](https://discuss.elastic.co/u/GKre)\
**Post date:** [November 7, 2024, 3:11pm UTC](https://discuss.elastic.co/t/scrinject-malware-was-detected/370156/3 "2024-11-07T15:11:30Z")

</div>

Thank you @ferullo,

here's the defender alert - no sensitive data so can be published:

11/2/2024 3:37:50 PM  
[1060] wininit.exe  
Process id 1060  
Execution details Elevated  
Image file path wininit.exe  
11/2/2024 3:37:50 PM  
[1176] services.exe  
Process id 1176  
Execution details Token elevation: Default, Integrity level: System  
Image file path C:\Windows\System32\services.exe  
Image file SHA1 395aa8b83cf4087ef62ca5407c6f69abf229411b  
Image file creation time Jun 25, 2024 12:11:51 PM  
Image file last modification time Jun 25, 2024 12:11:51 PM  
PE metadata services.exe  
User NT-AUTORITÄT\SYSTEM  
11/2/2024 3:37:52 PM  
[5160] elastic-endpoint.exe run  
Command line "elastic-endpoint.exe" run  
Process id 5160  
Execution details Token elevation: Default, Integrity level: System  
Image file path C:\Program Files\Elastic\Endpoint\elastic-endpoint.exe  
Image file SHA1 b3bd22b619b8c1fd965084edb6230a4d46d9f63e  
Image file creation time Jun 22, 2024 8:02:33 PM  
Image file last modification time Aug 19, 2024 3:12:17 PM  
PE metadata elastic-endpoint.exe  
User NT-AUTORITÄT\SYSTEM  
11/3/2024 5:23:45 PM  
elastic-endpoint.exe interacted with file elastic-agent-event-log-20241103-156.ndjson  
SHA1 1df5aa76f85185c8c721dfc0e5c4f94b0d404ebb  
Path C:\Program Files\Elastic\Agent\data\elastic-agent-8.15.0-25075f\logs\events\elastic-agent-event-log-20241103-156.ndjson  
Size 5 MB  
Remediation details Defender detected 'Trojan:HTML/ScrInject.TDAA!MTB' in file 'elastic-agent-event-log-20241103-156.ndjson', during attempted open by 'elastic-endpoint.exe'  
'ScrInject' malware was detected Resolved Detected Informational  
Additional related files

11/3/2024 5:23:45 PM  
elastic-agent-event-log-20241103-156.ndjson  
SHA1 1df5aa76f85185c8c721dfc0e5c4f94b0d404ebb  
Path C:\Program Files\Elastic\Agent\data\elastic-agent-8.15.0-25075f\logs\events\elastic-agent-event-log-20241103-156.ndjson  
Size 5 MB  
Remediation details Defender detected 'Trojan:HTML/ScrInject.TDAA!MTB' in file 'elastic-agent-event-log-20241103-156.ndjson', during attempted open by 'elastic-endpoint.exe'  
'ScrInject' malware was detected Resolved Detected Informational

Also - to make it more visible - as image:

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/2/f/2f8e00e3d0dbeead31ad2e98b5a6bc7642d7a5eb.png)

I checked for the .json file but it is not on the machine. If i find it somewhere i will upload.

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [November 7, 2024, 4:33pm UTC](https://discuss.elastic.co/t/scrinject-malware-was-detected/370156/4 "2024-11-07T16:33:11Z")

</div>

> [@GKre](#):
>
> I checked for the .json file but it is not on the machine. If i find it somewhere i will upload.

Double-check the extension. It appears to be `.ndjson` not `.json`. These `.ndjson` files are log files human-readable text logs. They don't contain executable code. This appears to be a false positive in MDE. Something in that log file is matching a signature in the MDE AV database.

I've created [a secure upload link](https://upload.elastic.co/u/f95ec1a2-acf5-4e2c-92e0-09408848cf06) specific to this case, if you'd like to share the file with us.

This Microsoft page documents how to suppress MDE alerts and/or report false positives to the MDE team:

- [Address false positives/negatives in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint | Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives)

---

<div class="post-metadata">

**Author:** ![GKre](https://avatars.discourse-cdn.com/v4/letter/g/ecae2f/32.png) [@GKre](https://discuss.elastic.co/u/GKre)\
**Post date:** [November 7, 2024, 8:19pm UTC](https://discuss.elastic.co/t/scrinject-malware-was-detected/370156/5 "2024-11-07T20:19:25Z")

</div>

thank you @gabriel.landau the extension was a typo. The file is no longer on the machine.  
As you mentioned i also think this is a false positive. And i changed the setting in defender to ignore this alert.  
Having a signature in a human readable file is something rare in my opinion.  
I will try to collect an evidence file so it can be investigated. Maybe i find some more info in the defender portal.  
Thank you for taking time and investigating.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2024, 8:20pm UTC](https://discuss.elastic.co/t/scrinject-malware-was-detected/370156/6 "2024-12-05T20:20:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
