<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: C2 threat Wgeneric.aazufa (threatid 269587899) in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c2-threat-wgeneric-aazufa-threatid-269587899/m-p/281466#M623</link>
    <description>&lt;P&gt;Thanks for the reply, it's the "looking into further" bit I was struggling with because "aazufa" doesn't seem to be a recognised virus/threat name according to Google and Palo don't publish any details saying why they think this is suspicious, so all the Palos are saying to me is "we think there's something fishy here and we have assigned a random string of characters to it which have no meaning at all"&lt;/P&gt;&lt;P&gt;It's not the first time I have had this and it's frustrating that Palo set up these signatures and detect "stuff" but there's no way to find out more about it so either I completely ignore the alerts and just accept the recommended behaviour or I completely ignore the alerts and let the traffic through.&amp;nbsp; The threat vault needs more information.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2019 08:21:17 GMT</pubDate>
    <dc:creator>djr</dc:creator>
    <dc:date>2019-08-07T08:21:17Z</dc:date>
    <item>
      <title>C2 threat Wgeneric.aazufa (threatid 269587899)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c2-threat-wgeneric-aazufa-threatid-269587899/m-p/279522#M614</link>
      <description>&lt;P&gt;I am seeing this traffic on my network from a particular user so thought I would just check out a bit about it, but I can't find any reference to aazufa on the web (via google) other than the threat vault entry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How come there is a threat which no-one seems to have heard of, and if Palo have made up the name, why doesn't the threat vault give the well-known name for the malware?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 06:50:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c2-threat-wgeneric-aazufa-threatid-269587899/m-p/279522#M614</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2019-07-26T06:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: C2 threat Wgeneric.aazufa (threatid 269587899)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c2-threat-wgeneric-aazufa-threatid-269587899/m-p/281398#M620</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What the PAN does is look at behaviour. Looks like the traffic got flagged but if you look at the name it has 'generic' in it. Meaning the PAN thought it looked suspicious and it should be checked out further.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 21:13:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c2-threat-wgeneric-aazufa-threatid-269587899/m-p/281398#M620</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-08-06T21:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: C2 threat Wgeneric.aazufa (threatid 269587899)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c2-threat-wgeneric-aazufa-threatid-269587899/m-p/281466#M623</link>
      <description>&lt;P&gt;Thanks for the reply, it's the "looking into further" bit I was struggling with because "aazufa" doesn't seem to be a recognised virus/threat name according to Google and Palo don't publish any details saying why they think this is suspicious, so all the Palos are saying to me is "we think there's something fishy here and we have assigned a random string of characters to it which have no meaning at all"&lt;/P&gt;&lt;P&gt;It's not the first time I have had this and it's frustrating that Palo set up these signatures and detect "stuff" but there's no way to find out more about it so either I completely ignore the alerts and just accept the recommended behaviour or I completely ignore the alerts and let the traffic through.&amp;nbsp; The threat vault needs more information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 08:21:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c2-threat-wgeneric-aazufa-threatid-269587899/m-p/281466#M623</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2019-08-07T08:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: C2 threat Wgeneric.aazufa (threatid 269587899)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c2-threat-wgeneric-aazufa-threatid-269587899/m-p/281507#M624</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;To be honest, I also struggle with the 'generic' ones. What I usualy do is get a pcap of the traffic and submit a ticket for support to take a look. It could be a false positive. I have my policies set to grab extended pcaps of the traffic automatically.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 13:44:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/c2-threat-wgeneric-aazufa-threatid-269587899/m-p/281507#M624</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-08-07T13:44:30Z</dc:date>
    </item>
  </channel>
</rss>

