<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: C&amp;amp;C Traffic Direction re China Chopper in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c-amp-c-traffic-direction-re-china-chopper/m-p/231231#M413</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would say as long as your PAN is blocking/dropping the traffic inbound, you should be OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can always open a TAC case to verify.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 18 Sep 2018 14:43:00 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-09-18T14:43:00Z</dc:date>
    <item>
      <title>C&amp;C Traffic Direction re China Chopper</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c-amp-c-traffic-direction-re-china-chopper/m-p/230667#M400</link>
      <description>&lt;P&gt;Hi,&amp;nbsp; sorry if this is a stupid question, maybe we need a Reddit-style "ELI5" forum ;o)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been turning a blind eye to a background hum of China Chopper alerts for some time, so I thought I would try to understand what is going on.&amp;nbsp; The thing is the threat reports are showing Inbound China Chopper C&amp;amp;C traffic to some of our servers.&amp;nbsp; It's presumably being dropped as per our profiles, but I am pretty sure we are not hosting C&amp;amp;C servers.&amp;nbsp; I could believe we somehow got infected but I would expect that would result in Outbound C&amp;amp;C traffic, so why would the C&amp;amp;C traffic be inbound to my servers from seemingly random internet sources?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 08:20:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c-amp-c-traffic-direction-re-china-chopper/m-p/230667#M400</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2018-09-13T08:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: C&amp;C Traffic Direction re China Chopper</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c-amp-c-traffic-direction-re-china-chopper/m-p/230734#M401</link>
      <description>&lt;P&gt;My experience with this is similar, I know we don't have any infections but we get frequent China Chopper packets&amp;nbsp;coming in. I have set the threatID to block because when I look at the Geo location of the source IP, it's always from questionable locations.&amp;nbsp; I have been blocking this traffic for two months without any issues.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 15:27:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c-amp-c-traffic-direction-re-china-chopper/m-p/230734#M401</guid>
      <dc:creator>smc007</dc:creator>
      <dc:date>2018-09-13T15:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: C&amp;C Traffic Direction re China Chopper</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c-amp-c-traffic-direction-re-china-chopper/m-p/231231#M413</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would say as long as your PAN is blocking/dropping the traffic inbound, you should be OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can always open a TAC case to verify.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 14:43:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c-amp-c-traffic-direction-re-china-chopper/m-p/231231#M413</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-18T14:43:00Z</dc:date>
    </item>
  </channel>
</rss>

