<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Completely puzzled - Unique Threat ID: 193986039 in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/completely-puzzled-unique-threat-id-193986039/m-p/204869#M270</link>
    <description>&lt;P&gt;&amp;nbsp;The domain was found to be queried by malicious samples of explorer.exe&lt;/P&gt;</description>
    <pubDate>Mon, 12 Mar 2018 17:27:53 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2018-03-12T17:27:53Z</dc:date>
    <item>
      <title>Completely puzzled - Unique Threat ID: 193986039</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/completely-puzzled-unique-threat-id-193986039/m-p/204599#M267</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did anyone had WildFire Threat events with the following Unique Threat ID: 193986039?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Threat Vault provided me the following information:&lt;/P&gt;&lt;P&gt;Signature&amp;nbsp;&lt;SPAN&gt;Release&lt;/SPAN&gt;&amp;nbsp;Domain Name&amp;nbsp;Type&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P class=""&gt;Name: generic:ecompassesfarringdon.com&lt;/P&gt;&lt;P class=""&gt;Unique Threat ID: 193986039&lt;/P&gt;&lt;P class=""&gt;Create Time: 2018-01-18 10:45:23 (UTC)&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="tabbed-header Pre-71"&gt;Threat ID: 4035508&lt;/P&gt;&lt;P class="tabbed-header Pre-71"&gt;Current Release: 2497 (2018-01-19 UTC)&lt;/P&gt;&lt;P class="tabbed-header Pre-71"&gt;First Release: 2497 (2018-01-19 UTC)&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A href="http://www.threecompassesfarringdon.com" target="_blank"&gt;www threecompassesfarringdon com&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;AntiVirus&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P class=""&gt;Name: generic:ecompassesfarringdon.com&lt;/P&gt;&lt;P class=""&gt;Unique Threat ID: 193986039&lt;/P&gt;&lt;P class=""&gt;Create Time: 2018-01-18 10:45:23 (UTC)&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="tabbed-header Pre-71"&gt;Threat ID: 3823708&lt;/P&gt;&lt;P class="tabbed-header Pre-71"&gt;Current Release: 155829 (2018-01-18 UTC)&lt;/P&gt;&lt;P class="tabbed-header Pre-71"&gt;First Release: 155829 (2018-01-18 UTC)&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A href="http://www.threecompassesfarringdon.com" target="_blank"&gt;www threecompassesfarringdon com&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;WildFire&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Being a Tucows domain (Domain Provider with a long story of Nefarious Activity) doesn't help, however the domain appears to be register under Squarespace Inc. which is a legite and known "website creation facilitator" type of company/software.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 17:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/completely-puzzled-unique-threat-id-193986039/m-p/204599#M267</guid>
      <dc:creator>Paulo_Henriques</dc:creator>
      <dc:date>2018-03-09T17:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Completely puzzled - Unique Threat ID: 193986039</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/completely-puzzled-unique-threat-id-193986039/m-p/204619#M269</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I dont have these on my PAN but dont think anyone in our company would go to that site. I checked a few sites to see if that one was malicious and they came up clean. You could always take some pcaps and have the PAN engineers take a look.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/url/1f0da1753dea79ab135de7a5abf3fd8a31b4446c2347d89300d33bd5355bed00/analysis/" target="_blank"&gt;https://www.virustotal.com/en/url/1f0da1753dea79ab135de7a5abf3fd8a31b4446c2347d89300d33bd5355bed00/analysis/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://quttera.com/sitescan/www.threecompassesfarringdon.com" target="_blank"&gt;https://quttera.com/sitescan/www.threecompassesfarringdon.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://sitecheck.sucuri.net/results/www.threecompassesfarringdon.com" target="_blank"&gt;https://sitecheck.sucuri.net/results/www.threecompassesfarringdon.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 20:22:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/completely-puzzled-unique-threat-id-193986039/m-p/204619#M269</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-09T20:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Completely puzzled - Unique Threat ID: 193986039</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/completely-puzzled-unique-threat-id-193986039/m-p/204869#M270</link>
      <description>&lt;P&gt;&amp;nbsp;The domain was found to be queried by malicious samples of explorer.exe&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 17:27:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/completely-puzzled-unique-threat-id-193986039/m-p/204869#M270</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-03-12T17:27:53Z</dc:date>
    </item>
  </channel>
</rss>

