Trojan:Script/Stealer.HBF!MTB

Malin Solvang Karlsen 0 Reputation points
2026-06-08T10:21:10.51+00:00

Hello. We recently had 2 incidents: Defender detected and terminated active 'Trojan:Script/Stealer.HBF!MTB' in process 'an unknown process' This seemes to come from Postman.

According to this post on reddit https://www.reddit.com/r/DefenderATP/comments/1tvioqt/appasar_postman_alert_mde/ this is a false positive.

Could you confirm that this is a false positive ?

Have tried to find the prosess ID - was unknown and i cant seem to fint it. have tried some threat hunting and checked entra sign in logs and audit logs and everything looks normal. have tried to get som more information about this. but the best i found was that reddit post.

Microsoft 365 and Office | Microsoft 365 Defender | Other | Other
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-06-08T10:21:30.3233333+00:00

    Confirmation of a specific detection as a false positive cannot be provided.

    To handle this case:

    1. Identify the detection source
      • In Microsoft Defender for Endpoint / Defender XDR, open the alert and check the alert source and detection source (for example, Antivirus, EDR, Custom TI, PUA protection, etc.).
      • Use the guidance in the "Identify the detection source" section to determine whether this came from Microsoft Defender Antivirus, EDR, custom indicators, or other components.
    2. Submit the file or detection as a possible false positive
      • For files or apps on a device that are suspected to be wrongly detected, submit the file to Microsoft for malware analysis using the Microsoft Security Intelligence submission site as described in Submit a file to Microsoft for malware analysis.
      • For Defender for Endpoint detections, use the guidance in Address false positives/negatives in Microsoft Defender for Endpoint and submit the false positive to the portal at https://aka.ms/wdsi.
    3. (Optional) Apply a temporary workaround if business‑critical
      • If the detection is blocking legitimate Postman usage and operations are impacted, use one of the documented workarounds while waiting for Microsoft’s verdict:
        • Create an Indicator – File hash – allow for the specific, verified‑safe file.
        • Or configure an appropriate Antivirus exclusion or EDR exclusion, or tune the alert, depending on the detection source.
      • These workarounds should be scoped as narrowly as possible and only applied after verifying the file’s legitimacy, because exclusions reduce protection.
    4. If this is part of a penetration test or controlled simulation
      • Follow the “How to submit possible false negatives for investigation” / diagnostic guidance when gathering logs and details (OrgID, DeviceID, binaries, timestamps, reproduction steps) so Microsoft can accurately assess whether the detection is correct or a false positive.
    5. Monitor for additional indicators
      • Continue reviewing Defender alerts, Advanced Hunting results, and Entra sign‑in/audit logs for any unusual activity, but rely on Microsoft’s submission response to determine whether the specific Trojan:Script/Stealer.HBF!MTB detection on Postman is ultimately classified as a false positive.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.