<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Colours Whatsapp Spyware in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/colours-whatsapp-spyware/m-p/430164#M1288</link>
    <description>&lt;P&gt;That's the domain of a malware site. There is a malicious JS file within that gets auto-loaded.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Aug 2021 17:25:41 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2021-08-30T17:25:41Z</dc:date>
    <item>
      <title>Colours Whatsapp Spyware</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/colours-whatsapp-spyware/m-p/429115#M1278</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing these alerts&amp;nbsp;&lt;SPAN&gt;GENERIC:COLORS.WHATSAP.TOP(345898629) on a regular basis recently, they start at random times and they persist for around an hour then drop.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Has anybody else seen this ? we have checked the host that is generating the alerts and there is no indication that it has been compromised by the above virus although the user does remember getting the email that is the delivery method of this two weeks ago but swears they did not click the link, anti-virus software is installed on the Apple device, the Firewall is Sinkholing the traffic so I am not too concerned for the corporate network, but any more information would be greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 12:50:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/colours-whatsapp-spyware/m-p/429115#M1278</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-08-25T12:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Colours Whatsapp Spyware</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/colours-whatsapp-spyware/m-p/430164#M1288</link>
      <description>&lt;P&gt;That's the domain of a malware site. There is a malicious JS file within that gets auto-loaded.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 17:25:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/colours-whatsapp-spyware/m-p/430164#M1288</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2021-08-30T17:25:41Z</dc:date>
    </item>
  </channel>
</rss>

