<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485084#M1615</link>
    <description>&lt;P&gt;I did a revert of Aplications and Threats to the previous version 8564&lt;/P&gt;</description>
    <pubDate>Thu, 05 May 2022 06:36:40 GMT</pubDate>
    <dc:creator>janekpalo</dc:creator>
    <dc:date>2022-05-05T06:36:40Z</dc:date>
    <item>
      <title>ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484588#M1605</link>
      <description>&lt;P&gt;Anyone else seeing a large number of threat alerts this morning for the new generic signatures added last night? Seeing dozens this morning coming from user document downloads from a trusted financial source. I haven't fully decrypted the data yet, but appears to be false positives. Anyone know exactly what all these new critical threat signatures are suppose to be targeting?&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 18:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484588#M1605</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-05-03T18:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484645#M1606</link>
      <description>&lt;P&gt;After collecting a bunch of data, it looks like all the 81845 signature hits have a single thing in common, a base64 encoded string of ASCII "2" characters in a row (in the middle of apparent binary data).&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 20:26:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484645#M1606</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-05-03T20:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484688#M1607</link>
      <description>&lt;P&gt;I extracted the packet dumps and compared across multiple different sites triggering the alert. The common string is a 622 byte JFIF v1.01 background image file with the "22222" string in it (more likely all pixels in a color channel set to the same value). The file seems to have a few anomalies, but I am not an expert on JFIF formatting. Nothing obviously wrong in the image and certainly not "PHP Webshell" code. The extracted JFIF file, by itself, triggers 81845 when passed thru the PA.&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 22:38:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484688#M1607</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-05-03T22:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484701#M1608</link>
      <description>&lt;P&gt;I am also seeing the same behavior on .aspx files to a selected website (prod/dev/test) flagging&amp;nbsp;&lt;SPAN&gt;81845.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 00:13:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484701#M1608</guid>
      <dc:creator>RyanMinty</dc:creator>
      <dc:date>2022-05-04T00:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484724#M1609</link>
      <description>&lt;P&gt;I have been seeing false positives on 81845 too. I have been carrying out exchange to 365 migrations for a week now fine, but for nearly a day I have been having transfers failing and lots of alerts(several times a minute) from our PAN showing 81845 threats being triggered. Given that our MS Exchange definitely is not using PHP it should not be getting caught on this one.&lt;BR /&gt;When I stop migrations, the alerts stop.&lt;/P&gt;&lt;P&gt;So this threat definition probably needs some tweaking to cut down on the false positives.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 05:07:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484724#M1609</guid>
      <dc:creator>Hindmarsh</dc:creator>
      <dc:date>2022-05-04T05:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484772#M1610</link>
      <description>&lt;P&gt;Looks like its been updated from last content update&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Applications and Threats Content Release Notes - Version 8565&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Modified Anti-Spyware Signatures (1)&lt;BR /&gt;Severity ID Attack Name Category Default Action Change Minimum PAN-OS Version Maximum PAN-OS Version&lt;BR /&gt;critical 81845 Generic PHP Webshell File Detection webshell reset-both improved detection logic to address a possible fp issue 8.1.0&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 09:35:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484772#M1610</guid>
      <dc:creator>RyanMinty</dc:creator>
      <dc:date>2022-05-04T09:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484805#M1611</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I also have this problem id 81845 (severity Critical) with user connections to the local web server on port 443 (web-browsing) and action reset-server.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 12:33:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/484805#M1611</guid>
      <dc:creator>janekpalo</dc:creator>
      <dc:date>2022-05-04T12:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485007#M1612</link>
      <description>&lt;P&gt;I created an anti-spyware profile with an exception for 81845 and applied it to the necessary policies until this is corrected/fine tuned.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 20:41:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485007#M1612</guid>
      <dc:creator>Gareth-Doyle</dc:creator>
      <dc:date>2022-05-04T20:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485008#M1613</link>
      <description>&lt;P&gt;The 8565 update to Applications and Threats database has fixed the issue for me so far. My test file is no longer triggering the alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159572"&gt;@Gareth-Doyle&lt;/a&gt;&amp;nbsp;Has you PA applied the update yet?&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 20:49:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485008#M1613</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-05-04T20:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485044#M1614</link>
      <description>&lt;P&gt;The update fixed the multiple issues I had. Rolling back the custom AS policy now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 22:57:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485044#M1614</guid>
      <dc:creator>RyanMinty</dc:creator>
      <dc:date>2022-05-04T22:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485084#M1615</link>
      <description>&lt;P&gt;I did a revert of Aplications and Threats to the previous version 8564&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 06:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485084#M1615</guid>
      <dc:creator>janekpalo</dc:creator>
      <dc:date>2022-05-05T06:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 81845 - Generic PHP Webshell File Detection false positives</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485503#M1616</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Latest Updates The signature 81845 has been revised to address the false positive issue and released on 05/03/2022 with the content update 8565.&lt;BR /&gt;This issue should be resolved if you update to content 8565 or higher.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 21:02:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threatid-81845-generic-php-webshell-file-detection-false/m-p/485503#M1616</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2022-05-06T21:02:22Z</dc:date>
    </item>
  </channel>
</rss>

