<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: suspicious user account  and file in my system in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-user-account-and-file-in-my-system/m-p/519346#M107683</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/252060"&gt;@pra838&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe&lt;SPAN&gt; a user trapsanalyzer1 is normal and created by Cortex XDR endpoint protection (or previously traps).&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When a file needs to be analyzed it will give the task to "analyzerd".&amp;nbsp; The job of it is to analyze the file and return a verdict.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 27 Oct 2022 08:06:24 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2022-10-27T08:06:24Z</dc:date>
    <item>
      <title>suspicious user account  and file in my system</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-user-account-and-file-in-my-system/m-p/519315#M107677</link>
      <description>&lt;P&gt;Is this BOT or not ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Open Sans"&gt;&lt;STRONG&gt;# cat /etc/passwd | grep trapsanalyzer1&lt;BR /&gt;&lt;I&gt;trapsanalyzer1:x:993:990::/home/trapsanalyzer1:/usr/sbin/nologin&lt;/I&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Open Sans"&gt;&lt;STRONG&gt;# &lt;STRONG&gt;chage -l trapsanalyzer1&lt;BR /&gt;&lt;I&gt;Last password change&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Jul 13, 2020&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Password expires&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : never&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Password inactive&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : never&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Account expires&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : never&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Minimum number of days between password change&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : -1&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Maximum number of days between password change&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : -1&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Number of days of warning before password expires&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : -1&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;# userdel -r trapsanalyzer1&lt;BR /&gt;&lt;I&gt;userdel: user trapsanalyzer1 is currently used by process 1137&lt;BR /&gt;&lt;BR /&gt;]&lt;STRONG&gt;# ps -ef | grep 1137&lt;BR /&gt;&lt;I&gt;trapsan+&amp;nbsp; 1137&amp;nbsp;&amp;nbsp; 744&amp;nbsp; 0 Sep25 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 /opt/traps/analyzerd/analyzerd 17 19 21&lt;I&gt;&lt;BR /&gt;&lt;I&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 26328 25808&amp;nbsp; 0 22:20 pts/0&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 grep --color=auto 1137&lt;BR /&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="Open Sans" color="#e20b0b"&gt;&lt;FONT face=""&gt;File :&lt;FONT face="Open Sans" color="#e20b0b"&gt;&lt;STRONG&gt;analyzerd&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Open Sans"&gt;# cd /opt/traps/analyzerd/&lt;BR /&gt;&lt;STRONG&gt;# ll&lt;BR /&gt;total 1972&lt;BR /&gt;&lt;I&gt;-r-xr-xr-x. 1 root root 2018616 Jul 13&amp;nbsp; 2020 analyzerd&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;# stat analyzerd&lt;BR /&gt;&lt;I&gt;&amp;nbsp; File: ‘analyzerd’&lt;I&gt;&lt;BR /&gt;&lt;I&gt;&amp;nbsp; Size: 2018616&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blocks: 3944&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IO Block: 4096&amp;nbsp;&amp;nbsp; regular file&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Device: fd01h/64769d&amp;nbsp;&amp;nbsp;&amp;nbsp; Inode: 509439873&amp;nbsp;&amp;nbsp; Links: 1&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Access: (0555/-r-xr-xr-x)&amp;nbsp; Uid: (&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/&amp;nbsp;&amp;nbsp;&amp;nbsp; root)&amp;nbsp;&amp;nbsp; Gid: (&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/&amp;nbsp;&amp;nbsp;&amp;nbsp; root)&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Access: 2022-10-19 22:10:58.555360195 +0530&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Modify: 2020-07-13 10:38:39.431252769 +0530&lt;I&gt;&lt;BR /&gt;&lt;I&gt;Change: 2020-07-13 10:39:04.990251201 +0530&lt;I&gt;&lt;BR /&gt;&lt;I&gt;&amp;nbsp;Birth: -&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Open Sans"&gt;&lt;I&gt;So , This is virustotal hash of analyzd file.&lt;/I&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="Open Sans"&gt;&lt;I&gt;0f762101141fae2791a810d99e69ec28358acef9c6491f79e9d13941c22ac4de&lt;/I&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="Open Sans"&gt;&lt;I&gt;&lt;A href="https://www.virustotal.com/graph/embed/g341095e131824f508d1d0cb150bc7da3ebddab77a09a46f98c5221ac813b602b" target="_blank" rel="noopener"&gt;https://www.virustotal.com/graph/embed/g341095e131824f508d1d0cb150bc7da3ebddab77a09a46f98c5221ac813b602b&lt;/A&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="Open Sans"&gt;&lt;I&gt;Is this is not a BOT and no need to take action to remove this?&lt;/I&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 04:18:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-user-account-and-file-in-my-system/m-p/519315#M107677</guid>
      <dc:creator>pra838</dc:creator>
      <dc:date>2022-10-27T04:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: suspicious user account  and file in my system</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-user-account-and-file-in-my-system/m-p/519346#M107683</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/252060"&gt;@pra838&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe&lt;SPAN&gt; a user trapsanalyzer1 is normal and created by Cortex XDR endpoint protection (or previously traps).&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When a file needs to be analyzed it will give the task to "analyzerd".&amp;nbsp; The job of it is to analyze the file and return a verdict.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 Oct 2022 08:06:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-user-account-and-file-in-my-system/m-p/519346#M107683</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-10-27T08:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: suspicious user account  and file in my system</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-user-account-and-file-in-my-system/m-p/519403#M107694</link>
      <description>&lt;P&gt;Thank You So much ...!&lt;span class="lia-unicode-emoji" title=":flexed_biceps:"&gt;💪&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;But what is the connection established to UK IPs.&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;&lt;STRONG&gt;And what is about &lt;EM&gt;Virustotal and VTGraphs&lt;/EM&gt;.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Do you have any idea about it?&lt;/P&gt;
&lt;P&gt;0f762101141fae2791a810d99e69ec28358acef9c6491f79e9d13941c22ac4de&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.virustotal.com/graph/embed/g341095e131824f508d1d0cb150bc7da3ebddab77a09a46f98c5221ac813b" target="_blank"&gt;https://www.virustotal.com/graph/embed/g341095e131824f508d1d0cb150bc7da3ebddab77a09a46f98c5221ac813b&lt;/A&gt;...&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 15:05:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-user-account-and-file-in-my-system/m-p/519403#M107694</guid>
      <dc:creator>pra838</dc:creator>
      <dc:date>2022-10-27T15:05:38Z</dc:date>
    </item>
  </channel>
</rss>

