<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Antivirus Signatures in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/245439#M291</link>
    <description>&lt;P&gt;If you had AutoFocus, you can check these hashes to see how we classify them, IOCs related to the file (if malicious), when it was first seen, and if there is any relevance to threat actors, malware campaigns, etc.&amp;nbsp; As a previous posted noted, Palo doesn't do signatures based on hash, as hashes are more unique than the malware itself and it would be inefficient to create hundreds/thousands or more of signatures for different hashes, especially if the underlying malware or virus is the same.&amp;nbsp; Palo cares more about&amp;nbsp; the underlying malicious file and its underlying activity.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jan 2019 00:18:47 GMT</pubDate>
    <dc:creator>dbilinski</dc:creator>
    <dc:date>2019-01-10T00:18:47Z</dc:date>
    <item>
      <title>Custom Antivirus Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/178320#M204</link>
      <description>&lt;P&gt;Is it possible to create custom antivirus signatures?&lt;/P&gt;&lt;P&gt;Goal is to block files with certain hashes. The original file is not available, only the hash.&lt;/P&gt;&lt;P&gt;Is there any way to submit hashes to PANW so that they create signatures? (Something similar like for URLs)&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 19:12:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/178320#M204</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2017-09-22T19:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Antivirus Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/178332#M205</link>
      <description>&lt;P&gt;If you can send us the hash we can look to try and find the file somewhere else and make a signature if the file is malicious, but we do not do hash based blocks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 20:39:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/178332#M205</guid>
      <dc:creator>tboire</dc:creator>
      <dc:date>2017-09-22T20:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Antivirus Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/178339#M206</link>
      <description>&lt;P&gt;Hello tboire,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thanks for your reply. It is regarding a recent ransomware campaign, e.g.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hash:&lt;/P&gt;&lt;P&gt;0f6ae637a9d15503a0af42be649388f01f8637ca16b15526e318a94b7f34bf6e&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cannot find in PA Threatvault, but Virustotal shows many vendors classify it as malware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hash:&lt;/P&gt;&lt;P&gt;39256f126bba17770310c2115586b9f22b858cf15c43ab36bd7cfb18ad63a0c2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is found in PA Threatvault as malware, but there seems to be no signature (nothing shown regarding which wildfire content update contains a signature to block it).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the only method would be to get hold of a sample file and upload to Wildfire portal in order to trigger analysis by PA and possibly signature creation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 20:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/178339#M206</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2017-09-22T20:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Antivirus Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/244167#M287</link>
      <description>&lt;P&gt;can you check these hashs&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New Hashes&lt;/P&gt;&lt;P&gt;e5bf756d5530ec38ff649b901b3c7506f8556821d979bdcb392237f2ff40daf8&lt;BR /&gt;5257f623270b4c5cc471ff35b1bfeec80ab37c7e012da76b50ebd2c4911a43d0&lt;BR /&gt;c3ab58b3154e5f5101ba74fccfd27a9ab445e41262cdf47e8cc3be7416a5904f&lt;BR /&gt;0694bdf9f08e4f4a09d13b7b5a68c0148ceb3fcc79442f4db2aa19dd23681afe&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Old Hashes&lt;/P&gt;&lt;P&gt;5203628a89e0a7d9f27757b347118250f5aa6d0685d156e375b6945c8c05eb8a&lt;BR /&gt;0266be9130bdf20976fc5490f9191edaafdae09ebe45e74cd97792412454bf0d&lt;BR /&gt;d9e52663715902e9ec51a7dd2fea5241c9714976e9541c02df66d1a42a3a7d2a&amp;nbsp;&lt;BR /&gt;35ceb84403efa728950d2cc8acb571c61d3a90decaf8b1f2979eaf13811c146b&lt;BR /&gt;0975eb436fb4adb9077c8e99ea6d34746807bc83a228b17d321d14dfbbe80b03&lt;BR /&gt;391e7b90bf3f0bfeb2c2602cc65aa6be4dd1c01374b89c4a48425f2d22fe231c&lt;BR /&gt;6985ef5809d0789eeff623cd2436534b818fd2843f09fa2de2b4a6e2c0e1a879&lt;BR /&gt;ccb1209122085bed5bded3f923835a65d3cc1071f7e4ad52bc5cf42057dd2150&lt;BR /&gt;dab3308ab60d0d8acb3611bf364e81b63cfb6b4c1783864ebc515297e2297589&lt;BR /&gt;bc4513e1ea20e11d00cfc6ce899836e4f18e4b5f5beee52e0ea9942adb78fc70&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/715"&gt;@Anon1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Is it possible to create custom antivirus signatures?&lt;/P&gt;&lt;P&gt;Goal is to block files with certain hashes. The original file is not available, only the hash.&lt;/P&gt;&lt;P&gt;Is there any way to submit hashes to PANW so that they create signatures? (Something similar like for URLs)&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 21:08:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/244167#M287</guid>
      <dc:creator>Eng-nezar</dc:creator>
      <dc:date>2018-12-20T21:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Antivirus Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/245439#M291</link>
      <description>&lt;P&gt;If you had AutoFocus, you can check these hashes to see how we classify them, IOCs related to the file (if malicious), when it was first seen, and if there is any relevance to threat actors, malware campaigns, etc.&amp;nbsp; As a previous posted noted, Palo doesn't do signatures based on hash, as hashes are more unique than the malware itself and it would be inefficient to create hundreds/thousands or more of signatures for different hashes, especially if the underlying malware or virus is the same.&amp;nbsp; Palo cares more about&amp;nbsp; the underlying malicious file and its underlying activity.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 00:18:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-antivirus-signatures/m-p/245439#M291</guid>
      <dc:creator>dbilinski</dc:creator>
      <dc:date>2019-01-10T00:18:47Z</dc:date>
    </item>
  </channel>
</rss>

