<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Suspicious Code in GIF File Detection - Logic of Detection in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/suspicious-code-in-gif-file-detection-logic-of-detection/m-p/527648#M780</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Good Day Team!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I hope You are all doing well!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We have a detection re: a remote ip attempting to connect to a certain server which hit the rule &lt;STRONG&gt;Suspicious Code in GIF File Detection&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We have blocked the ip, however, the detection has:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Threat Category:&lt;/STRONG&gt; downloader&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PA Subtype (custom):&lt;/STRONG&gt; spyware&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;wherein we are currently in a dilemma if the former remediation is enough due to the lesser knowledge of the&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;logic&lt;/STRONG&gt;&lt;/EM&gt; of the Suspicious Code in GIF File &lt;STRONG&gt;&lt;EM&gt;rule&lt;/EM&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Does this detection (Suspicious Code in GIF File):&lt;/P&gt;
&lt;P&gt;- Scans/Detect network traffic, or&lt;/P&gt;
&lt;P&gt;- it scans file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please kindly let me know if You have any questions or clarification of this inquiry.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Thank You!&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 06:20:01 GMT</pubDate>
    <dc:creator>boy_pugante</dc:creator>
    <dc:date>2023-01-19T06:20:01Z</dc:date>
    <item>
      <title>Suspicious Code in GIF File Detection - Logic of Detection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/suspicious-code-in-gif-file-detection-logic-of-detection/m-p/527648#M780</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Good Day Team!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I hope You are all doing well!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We have a detection re: a remote ip attempting to connect to a certain server which hit the rule &lt;STRONG&gt;Suspicious Code in GIF File Detection&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We have blocked the ip, however, the detection has:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Threat Category:&lt;/STRONG&gt; downloader&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PA Subtype (custom):&lt;/STRONG&gt; spyware&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;wherein we are currently in a dilemma if the former remediation is enough due to the lesser knowledge of the&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;logic&lt;/STRONG&gt;&lt;/EM&gt; of the Suspicious Code in GIF File &lt;STRONG&gt;&lt;EM&gt;rule&lt;/EM&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Does this detection (Suspicious Code in GIF File):&lt;/P&gt;
&lt;P&gt;- Scans/Detect network traffic, or&lt;/P&gt;
&lt;P&gt;- it scans file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please kindly let me know if You have any questions or clarification of this inquiry.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Thank You!&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 06:20:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/suspicious-code-in-gif-file-detection-logic-of-detection/m-p/527648#M780</guid>
      <dc:creator>boy_pugante</dc:creator>
      <dc:date>2023-01-19T06:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious Code in GIF File Detection - Logic of Detection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/suspicious-code-in-gif-file-detection-logic-of-detection/m-p/529367#M835</link>
      <description>&lt;P&gt;As this seems blocked by the spyware profile that together with the vunrability profile is network based (wildfire and the antivirus profiles are file based) it is more a network traffic than a file scan as GIF is also not supported for wildfire scans.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/wildfire-overview/wildfire-concepts/file-analysis" target="_blank"&gt;https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/wildfire-overview/wildfire-concepts/file-analysis&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the future maybe this can also be blocked as a file with advanced wildfire but for now it seems like a network signature.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/content-inspection-features/vuln-protection-inline-cloud-analysis" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/content-inspection-features/vuln-protection-inline-cloud-analysis&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 21:09:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/suspicious-code-in-gif-file-detection-logic-of-detection/m-p/529367#M835</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-01-31T21:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious Code in GIF File Detection - Logic of Detection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/suspicious-code-in-gif-file-detection-logic-of-detection/m-p/530773#M893</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Good Day Sir!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You for Your immediate and kind response!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Indeed, per our further checking and re-analysis this is a network based, although per Our discussion this could be on the &lt;STRONG&gt;gray area &lt;/STRONG&gt;due to some difficulties, we have somehow narrowed and remediated this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hoping to hear again from You soon!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Boy Pugante&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2023 11:17:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/suspicious-code-in-gif-file-detection-logic-of-detection/m-p/530773#M893</guid>
      <dc:creator>boy_pugante</dc:creator>
      <dc:date>2023-02-11T11:17:55Z</dc:date>
    </item>
  </channel>
</rss>

