Unknown file extentions tripped ransomware protection while saving files with known type extentions
Applies to
- ONTAP 9
- Anti-ransomware (ARW)
- MacOS
Issue
- While saving PDFs in MacOS, an ARW surge is observed with file extensions that have random letters and numbers:
Cluster1::> security anti-ransomware volume workload-behavior show -vserver svm1 -volume vol1
Vserver: svm1
Volume: vol1
File Extensions Observed: pdf, txt, tmp, xlsx, html,
pptx, 3gp, pper, csv, msg,
docx, xls, dat, sav, rds
........
Newly Observed File Extensions: DbncsA, MWID9A, FqIpKb,
Jbi0n7, S5UfAq, zWf3mK,
YTEUt6, jXX0fd, MLVBuB,
K831iM, yygW2C, gsMac0,
A9tAPu, WKDml3, OBMP9A,
0WkUqh, KfME03, mpGjV2,
k4vAsB, gMSE2P, U7fTeb
Number of Newly Observed File Extensions: 1, 1, 1, 1, 1, 1, 1, 1, 1, 1,
1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1