<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Azure Windows Defender alerted to Phonzy.A!ml in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-windows-defender-alerted-to-phonzy-a-ml/m-p/590948#M2208</link>
    <description>&lt;P&gt;Getting an alert from Azure defender and unable to find any reference regarding the alert in the community sections.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="fxc-gc-cell-content_1_0" class="fxc-gc-cell fxc-gc-columncell_1_0" role="gridcell" aria-readonly="true"&gt;
&lt;DIV class="fxc-gc-text"&gt;pps_parport.ko&amp;nbsp; &amp;nbsp;&lt;SPAN&gt;/usr/lib/modules/4.18.0-80.11.2.10.pan.x86_64/kernel/drivers/pps/clients&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;'Phonzy' malware was detected (Agentless)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;
&lt;DIV id="fxc-gc-cell-content_4_0" class="fxc-gc-cell fxc-gc-columncell_4_0" role="gridcell" aria-readonly="true"&gt;
&lt;DIV class="fxc-gc-text"&gt;Trojan:Script/Phonzy.B!ml&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="fxc-gc-cell-content_4_1" class="fxc-gc-cell fxc-gc-columncell_4_1" role="gridcell" aria-readonly="true"&gt;
&lt;DIV class="fxc-gc-text"&gt;Trojan&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="fxc-gc-cell-content_4_2" class="fxc-gc-cell fxc-gc-columncell_4_2" role="gridcell" aria-readonly="true"&gt;
&lt;DIV class="fxc-gc-text"&gt;pps_parport.ko&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;has anyone seen this and is this a result of the CVE issue?&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 02 Jul 2024 15:40:50 GMT</pubDate>
    <dc:creator>Keough</dc:creator>
    <dc:date>2024-07-02T15:40:50Z</dc:date>
    <item>
      <title>Azure Windows Defender alerted to Phonzy.A!ml</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-windows-defender-alerted-to-phonzy-a-ml/m-p/590948#M2208</link>
      <description>&lt;P&gt;Getting an alert from Azure defender and unable to find any reference regarding the alert in the community sections.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="fxc-gc-cell-content_1_0" class="fxc-gc-cell fxc-gc-columncell_1_0" role="gridcell" aria-readonly="true"&gt;
&lt;DIV class="fxc-gc-text"&gt;pps_parport.ko&amp;nbsp; &amp;nbsp;&lt;SPAN&gt;/usr/lib/modules/4.18.0-80.11.2.10.pan.x86_64/kernel/drivers/pps/clients&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;'Phonzy' malware was detected (Agentless)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;
&lt;DIV id="fxc-gc-cell-content_4_0" class="fxc-gc-cell fxc-gc-columncell_4_0" role="gridcell" aria-readonly="true"&gt;
&lt;DIV class="fxc-gc-text"&gt;Trojan:Script/Phonzy.B!ml&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="fxc-gc-cell-content_4_1" class="fxc-gc-cell fxc-gc-columncell_4_1" role="gridcell" aria-readonly="true"&gt;
&lt;DIV class="fxc-gc-text"&gt;Trojan&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="fxc-gc-cell-content_4_2" class="fxc-gc-cell fxc-gc-columncell_4_2" role="gridcell" aria-readonly="true"&gt;
&lt;DIV class="fxc-gc-text"&gt;pps_parport.ko&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;has anyone seen this and is this a result of the CVE issue?&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="fxc-gc-text"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Jul 2024 15:40:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-windows-defender-alerted-to-phonzy-a-ml/m-p/590948#M2208</guid>
      <dc:creator>Keough</dc:creator>
      <dc:date>2024-07-02T15:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Windows Defender alerted to Phonzy.A!ml</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-windows-defender-alerted-to-phonzy-a-ml/m-p/590983#M2209</link>
      <description>&lt;P&gt;Hi &lt;SPAN style="color:var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/338152"&gt;@Keough&lt;/a&gt;&lt;/SPAN&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am also unable to find references regarding this. Are there additional details to the alert? Did they provide a hash? I would recommend creating a case with MS Defender to understand the nature of this detection. &amp;nbsp;You can also compare the verdict with another vendor as well and enter it into WF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2024 05:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-windows-defender-alerted-to-phonzy-a-ml/m-p/590983#M2209</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-07-03T05:45:32Z</dc:date>
    </item>
  </channel>
</rss>

