<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR is unable to block USB viruses - the reason is unknown. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-is-unable-to-block-usb-viruses-the-reason-is-unknown/m-p/590161#M6839</link>
    <description>&lt;P&gt;We recently encountered an issue where a user's computer got infected with a USB virus after inserting a USB drive. The virus uses USB Driver.exe to create some directories and malicious programs as shown in the attached image. Additionally, it uses vmnet.exe to load these DLL files. However, Cortex XDR did not block it.&lt;/P&gt;
&lt;P&gt;We have already enabled the blocking rules in the Malware settings, but it did not take effect. We also created BIOC rules using the hashes of these files and configured it to block these DLL files when they are loaded [under Restrictions &amp;gt;&amp;gt; Custom Prevention Rules (we have enabled and applied these BIOC rules)], but this method still did not block them.&lt;/P&gt;
&lt;P&gt;However, when using another computer without Cortex XDR installed, Windows Defender was able to block this behavior. Is there any other method to make Cortex XDR block this behavior?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IOC Sha256&amp;nbsp;&lt;/P&gt;
&lt;P&gt;f985ac059ee73509750b7558e7482d69e37db280b484d1c728efcd49bf6f58a7&lt;/P&gt;
&lt;P&gt;fd2a17e747fac2b5fcba3ea714a811baaa83f5c47625579c32b969c574c5ef24&lt;/P&gt;
&lt;P&gt;fb73a819b37523126c7708a1d06f3b8825fa60c926154ab2d511ba668f49dc4b&lt;/P&gt;
&lt;P&gt;986ea546af34333c4b50e64a8b8712aa7643bb74aed8c48c789abcd51972dfaf&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2024 04:47:42 GMT</pubDate>
    <dc:creator>kentwuhc</dc:creator>
    <dc:date>2024-06-24T04:47:42Z</dc:date>
    <item>
      <title>Cortex XDR is unable to block USB viruses - the reason is unknown.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-is-unable-to-block-usb-viruses-the-reason-is-unknown/m-p/590161#M6839</link>
      <description>&lt;P&gt;We recently encountered an issue where a user's computer got infected with a USB virus after inserting a USB drive. The virus uses USB Driver.exe to create some directories and malicious programs as shown in the attached image. Additionally, it uses vmnet.exe to load these DLL files. However, Cortex XDR did not block it.&lt;/P&gt;
&lt;P&gt;We have already enabled the blocking rules in the Malware settings, but it did not take effect. We also created BIOC rules using the hashes of these files and configured it to block these DLL files when they are loaded [under Restrictions &amp;gt;&amp;gt; Custom Prevention Rules (we have enabled and applied these BIOC rules)], but this method still did not block them.&lt;/P&gt;
&lt;P&gt;However, when using another computer without Cortex XDR installed, Windows Defender was able to block this behavior. Is there any other method to make Cortex XDR block this behavior?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IOC Sha256&amp;nbsp;&lt;/P&gt;
&lt;P&gt;f985ac059ee73509750b7558e7482d69e37db280b484d1c728efcd49bf6f58a7&lt;/P&gt;
&lt;P&gt;fd2a17e747fac2b5fcba3ea714a811baaa83f5c47625579c32b969c574c5ef24&lt;/P&gt;
&lt;P&gt;fb73a819b37523126c7708a1d06f3b8825fa60c926154ab2d511ba668f49dc4b&lt;/P&gt;
&lt;P&gt;986ea546af34333c4b50e64a8b8712aa7643bb74aed8c48c789abcd51972dfaf&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 04:47:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-is-unable-to-block-usb-viruses-the-reason-is-unknown/m-p/590161#M6839</guid>
      <dc:creator>kentwuhc</dc:creator>
      <dc:date>2024-06-24T04:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR is unable to block USB viruses - the reason is unknown.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-is-unable-to-block-usb-viruses-the-reason-is-unknown/m-p/590488#M6856</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/228205"&gt;@kentwuhc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity. Since this requires investigation of activity to find the root cause please open a support case. Support team will be able to help you with blocking of this malware.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 14:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-is-unable-to-block-usb-viruses-the-reason-is-unknown/m-p/590488#M6856</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-06-26T14:15:17Z</dc:date>
    </item>
  </channel>
</rss>

