<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTP Evasion Detection (id:30401) in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ftp-evasion-detection-id-30401/m-p/1238597#M6314</link>
    <description>&lt;P&gt;Could anyone help to explain what this threat is?&lt;/P&gt;
&lt;P&gt;FTP evasion detection (id:30401)&lt;BR /&gt;&lt;BR /&gt;I found this threat in the log, also checked the logs in FTP server, but don't get it.&lt;/P&gt;
&lt;P&gt;here is the log from the source IP of this threat in FTP server (Microsoft IIS FTP).&lt;/P&gt;
&lt;PRE&gt;2025-09-16 04:43:54 8.34.210.54 - 10.10.10.31 21 ControlChannelOpened - - 0 0 8bb7b510-d8db-4808-94f0-4177688239fa -&lt;BR /&gt;2025-09-16 04:43:54 8.34.210.54 - 10.10.10.31 21 ControlChannelClosed - - 0 0 8bb7b510-d8db-4808-94f0-4177688239fa -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 ControlChannelOpened - - 0 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 - - 451 87 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 - - 451 87 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 - - 451 87 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 + - 500 87 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 ControlChannelClosed - - 1292 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;/PRE&gt;
&lt;P&gt;I can not find any info about this threat when I dig the internet.&lt;BR /&gt;Thank you!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Sep 2025 03:05:31 GMT</pubDate>
    <dc:creator>YanQian</dc:creator>
    <dc:date>2025-09-24T03:05:31Z</dc:date>
    <item>
      <title>FTP Evasion Detection (id:30401)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ftp-evasion-detection-id-30401/m-p/1238597#M6314</link>
      <description>&lt;P&gt;Could anyone help to explain what this threat is?&lt;/P&gt;
&lt;P&gt;FTP evasion detection (id:30401)&lt;BR /&gt;&lt;BR /&gt;I found this threat in the log, also checked the logs in FTP server, but don't get it.&lt;/P&gt;
&lt;P&gt;here is the log from the source IP of this threat in FTP server (Microsoft IIS FTP).&lt;/P&gt;
&lt;PRE&gt;2025-09-16 04:43:54 8.34.210.54 - 10.10.10.31 21 ControlChannelOpened - - 0 0 8bb7b510-d8db-4808-94f0-4177688239fa -&lt;BR /&gt;2025-09-16 04:43:54 8.34.210.54 - 10.10.10.31 21 ControlChannelClosed - - 0 0 8bb7b510-d8db-4808-94f0-4177688239fa -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 ControlChannelOpened - - 0 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 - - 451 87 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 - - 451 87 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 - - 451 87 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 + - 500 87 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;BR /&gt;2025-09-16 04:43:55 8.34.210.54 - 10.10.10.31 21 ControlChannelClosed - - 1292 0 959e077c-bc84-48c0-bbc1-4ad7af838dc4 -&lt;/PRE&gt;
&lt;P&gt;I can not find any info about this threat when I dig the internet.&lt;BR /&gt;Thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 03:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ftp-evasion-detection-id-30401/m-p/1238597#M6314</guid>
      <dc:creator>YanQian</dc:creator>
      <dc:date>2025-09-24T03:05:31Z</dc:date>
    </item>
  </channel>
</rss>

