Share via

Microsoft Security Intelligence Malware Submissions All "In Progress" or "Submitted" For 2 Weeks

Kevin-2125 80 Reputation points
2025-12-31T20:09:00.2966667+00:00

I have multiple files that all flagged with other antimalware for suspicious behavior/MITRE analysis issues, or were explicitly detected as Rhadamanthys. All of the malware, including other issues that are being detected in %appdata% and browser cache appear to be extremely evasive. They actively disable/counter numerous forms of fairly extensive antimalware including while airgapped as well as in safemode. They also appear to be actively deleting/tampering with contents of log files for local Microsoft antimalware tools. Pdf files, especially in business/job and education contexts, appear to be constantly a problem.

The files that are stuck as "In progress" are all showing an information box that they contain "an extremely large number of individual files" despite being literally a single .pdf file that is uploaded, not a large amount of individual files. This doesn't factually make any sense.

Another individual .pdf isnt even "In progress." It is still stuck as "Submitted."

What is going on with these?

User's image

Microsoft Security | Microsoft Defender | Other

2 answers

Sort by: Most helpful
  1. Kevin-2125 80 Reputation points
    2026-01-07T22:39:34.9133333+00:00

    Bump because this is still a problem. Still no change in status, response on this post nor several somewhat similar posts that I have found.

    User's image

    Was this answer helpful?

    0 comments No comments

  2. Kevin-2125 80 Reputation points
    2025-12-31T20:38:17.38+00:00

    Also I want to emphasize that with 2 weeks gone, submission details in submission history are noted to only be retained for "up to 30 days." That is basically halfway done at this point. The lack of time/retention as well as lack of email/multichannel notification of response/status change based upon what I have read, considering these still haven't been analyzed, are reasonably predictable potential problems as far as practical response/remediation/monitoring.

    User's image

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.