<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom Threat Signature for unique EXE files in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-threat-signature-for-unique-exe-files/m-p/94332#M108</link>
    <description>&lt;P&gt;DISCLAIMER:&lt;/P&gt;&lt;P&gt;As with all custom signatures on this forum, this signature is being provided by the author as a result of enthusiasm for the product and to share ideas with the Palo Alto Networks security community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Not recommended for deployment in a production network of any kind without internal testing.&lt;/P&gt;&lt;P&gt;- Not a solution to any vulnerability.&lt;/P&gt;&lt;P&gt;- Not an official supported Palo Alto Networks signature&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This write up is to help the Palo Alto Networks community with detecting a specific PE file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The sample signature was created on PAN OS Version 7.0.x :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SHA256: 92914013abfd071b0513d366bcaead978dce2f552c9d2853f4ce775604fb841f&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fill out the appropriate field under the configuration tab&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CustomVuln1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4608i1BD592A076D4ED5D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CustomVuln1.png" alt="CustomVuln1.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;Choose the standard option from the radio button and click on add to create a signature&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="customVuln2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4606i39F89C607B5F50AC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="customVuln2.png" alt="customVuln2.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;Since we only have one condition it doesn’t matter if we choose the ‘and’/’or’ condition&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="customVuln3.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4607i72DED325A49B266A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="customVuln3.png" alt="customVuln3.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To determine a unique string the *NIX utility xxd was used in this case, however any hex editor will work for this purpose.&amp;nbsp; The string was then converted to hex and used in a pattern match to detect the file. In this case the author of the file put what we believe to be their name in the file and that was used as a unique identifier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cusomVuln4.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4605iB76EEA4EACDF4BE9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cusomVuln4.png" alt="cusomVuln4.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="customVuln5.png" style="width: 768px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4610i330E0E615120B90D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="customVuln5.png" alt="customVuln5.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once this custom signature is applied and a web browser is used to attempt to download the file the firewall will either block or alert on detection depending on the action you set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="customVuln6.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4609i94CFF69931094CFD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="customVuln6.png" alt="customVuln6.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2016 16:43:22 GMT</pubDate>
    <dc:creator>tboire</dc:creator>
    <dc:date>2016-07-05T16:43:22Z</dc:date>
    <item>
      <title>Custom Threat Signature for unique EXE files</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-threat-signature-for-unique-exe-files/m-p/94332#M108</link>
      <description>&lt;P&gt;DISCLAIMER:&lt;/P&gt;&lt;P&gt;As with all custom signatures on this forum, this signature is being provided by the author as a result of enthusiasm for the product and to share ideas with the Palo Alto Networks security community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Not recommended for deployment in a production network of any kind without internal testing.&lt;/P&gt;&lt;P&gt;- Not a solution to any vulnerability.&lt;/P&gt;&lt;P&gt;- Not an official supported Palo Alto Networks signature&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This write up is to help the Palo Alto Networks community with detecting a specific PE file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The sample signature was created on PAN OS Version 7.0.x :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SHA256: 92914013abfd071b0513d366bcaead978dce2f552c9d2853f4ce775604fb841f&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fill out the appropriate field under the configuration tab&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CustomVuln1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4608i1BD592A076D4ED5D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CustomVuln1.png" alt="CustomVuln1.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;Choose the standard option from the radio button and click on add to create a signature&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="customVuln2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4606i39F89C607B5F50AC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="customVuln2.png" alt="customVuln2.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;Since we only have one condition it doesn’t matter if we choose the ‘and’/’or’ condition&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="customVuln3.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4607i72DED325A49B266A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="customVuln3.png" alt="customVuln3.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To determine a unique string the *NIX utility xxd was used in this case, however any hex editor will work for this purpose.&amp;nbsp; The string was then converted to hex and used in a pattern match to detect the file. In this case the author of the file put what we believe to be their name in the file and that was used as a unique identifier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cusomVuln4.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4605iB76EEA4EACDF4BE9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cusomVuln4.png" alt="cusomVuln4.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="customVuln5.png" style="width: 768px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4610i330E0E615120B90D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="customVuln5.png" alt="customVuln5.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once this custom signature is applied and a web browser is used to attempt to download the file the firewall will either block or alert on detection depending on the action you set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="customVuln6.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4609i94CFF69931094CFD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="customVuln6.png" alt="customVuln6.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 16:43:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-threat-signature-for-unique-exe-files/m-p/94332#M108</guid>
      <dc:creator>tboire</dc:creator>
      <dc:date>2016-07-05T16:43:22Z</dc:date>
    </item>
  </channel>
</rss>

