<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2024-3400 IOC's in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2024-3400-ioc-s/m-p/584578#M116763</link>
    <description>&lt;P&gt;Thanks for sharing&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2024 00:56:36 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2024-04-23T00:56:36Z</dc:date>
    <item>
      <title>CVE-2024-3400 IOC's</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2024-3400-ioc-s/m-p/584343#M116721</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;Its a twitter link but will try and summarize the process.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://twitter.com/cyb3rops/status/1781294529586331650" target="_blank" rel="noopener"&gt;https://twitter.com/cyb3rops/status/1781294529586331650&lt;/A&gt;&lt;/P&gt;
&lt;DIV class="css-175oi2r r-1awozwy r-18u37iz r-1wbh5a2 r-dnmrzs"&gt;
&lt;DIV class="css-175oi2r r-1wbh5a2 r-dnmrzs"&gt;
&lt;DIV class="css-175oi2r r-1awozwy r-18u37iz r-1wbh5a2 r-dnmrzs"&gt;
&lt;DIV class="css-1rynq56 r-bcqeeo r-qvutc0 r-37j5jr r-a023e6 r-rjixqe r-b88u0q r-1awozwy r-6koalj r-1udh08x r-3s2u2q r-1ddef8g" dir="ltr"&gt;&lt;SPAN class="css-1qaijid r-dnmrzs r-1udh08x r-3s2u2q r-bcqeeo r-qvutc0 r-poiln3"&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3"&gt;Credit to:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="css-1rynq56 r-bcqeeo r-qvutc0 r-37j5jr r-a023e6 r-rjixqe r-b88u0q r-1awozwy r-6koalj r-1udh08x r-3s2u2q r-1ddef8g" dir="ltr"&gt;&lt;SPAN class="css-1qaijid r-dnmrzs r-1udh08x r-3s2u2q r-bcqeeo r-qvutc0 r-poiln3"&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3"&gt;Florian Roth&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="css-1rynq56 r-bcqeeo r-qvutc0 r-37j5jr r-a023e6 r-rjixqe r-16dba41 r-xoduu5 r-18u37iz r-1q142lx" dir="ltr"&gt;&lt;SPAN&gt;@cyb3rops&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="css-175oi2r"&gt;
&lt;DIV class="css-175oi2r r-1s2bzr4"&gt;
&lt;DIV id="id__lqdzripxg8s" class="css-1rynq56 r-bcqeeo r-qvutc0 r-37j5jr r-1inkyih r-16dba41 r-bnwqim r-135wba7" dir="auto" lang="en" data-testid="tweetText"&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3"&gt;We decided to share our &lt;/SPAN&gt;&lt;SPAN class="r-18u37iz"&gt;&lt;A class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-1loqt21" dir="ltr" role="link" href="https://twitter.com/hashtag/YARA?src=hashtag_click" target="_blank" rel="noopener"&gt;#YARA&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3"&gt; rules to scan for indicators of the exploitation of CVE-2024-3400 in &lt;/SPAN&gt;&lt;SPAN class="r-18u37iz"&gt;&lt;A class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-1loqt21" dir="ltr" role="link" href="https://twitter.com/hashtag/PaloAlto?src=hashtag_click" target="_blank" rel="noopener"&gt;#PaloAlto&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3"&gt;'s PAN-OS with the community and included some of the generic rules (detect similar attacks) Three Steps &lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="css-1rynq56 r-bcqeeo r-qvutc0 r-37j5jr r-1inkyih r-16dba41 r-bnwqim r-135wba7" dir="auto" lang="en" data-testid="tweetText"&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3"&gt;1. Generate a Tech Support file and extract it &lt;/SPAN&gt;&lt;A class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-1loqt21" dir="ltr" role="link" href="https://t.co/ITPOvDtw7U" target="_blank" rel="noopener noreferrer nofollow"&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-qlhcfr r-qvk6io" aria-hidden="true"&gt;https://&lt;/SPAN&gt;knowledgebase.paloaltonetworks.com/KCSArticleDeta&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-qlhcfr r-qvk6io" aria-hidden="true"&gt;il?id=kA10g000000ClRlCAK&lt;/SPAN&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-lrvibr" aria-hidden="true"&gt;…&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="css-1rynq56 r-bcqeeo r-qvutc0 r-37j5jr r-1inkyih r-16dba41 r-bnwqim r-135wba7" dir="auto" lang="en" data-testid="tweetText"&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3"&gt;2. Download and extract THOR Lite &lt;/SPAN&gt;&lt;A class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-1loqt21" dir="ltr" role="link" href="https://t.co/EVPjanmunk" target="_blank" rel="noopener noreferrer nofollow"&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-qlhcfr r-qvk6io" aria-hidden="true"&gt;https://&lt;/SPAN&gt;nextron-systems.com/thor-lite/&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="css-1rynq56 r-bcqeeo r-qvutc0 r-37j5jr r-1inkyih r-16dba41 r-bnwqim r-135wba7" dir="auto" lang="en" data-testid="tweetText"&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3"&gt;3. Scan the extracted folder (tech support files) thor64-lite.exe -a FileScan -p ..\2024XXXX_XXXX_techsupport.tgz_unpacked --intense --cross-platform --max-file-size 500MB YARA Rules (already included in THOR Lite's signature package) &lt;/SPAN&gt;&lt;A class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-1loqt21" dir="ltr" role="link" href="https://t.co/qMgto8kP9k" target="_blank" rel="noopener noreferrer nofollow"&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-qlhcfr r-qvk6io" aria-hidden="true"&gt;https://&lt;/SPAN&gt;github.com/Neo23x0/signat&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-qlhcfr r-qvk6io" aria-hidden="true"&gt;ure-base/blob/master/yara/vuln_paloalto_cve_2024_3400_apr24.yar&lt;/SPAN&gt;&lt;SPAN class="css-1qaijid r-bcqeeo r-qvutc0 r-poiln3 r-lrvibr" aria-hidden="true"&gt;…&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="css-175oi2r"&gt;
&lt;DIV id="id__zdu545mgs" class="css-175oi2r r-9aw3ui r-1s2bzr4" aria-labelledby="id__3805k9f3i45 id__03mr2g14mtoo"&gt;
&lt;DIV class="css-175oi2r r-9aw3ui"&gt;
&lt;DIV class="css-175oi2r"&gt;
&lt;DIV class="css-175oi2r"&gt;
&lt;DIV class="css-175oi2r r-1kqtdi0 r-1phboty r-rs99b7 r-1867qdf r-1udh08x r-o7ynqc r-6416eg r-1ny4l3l"&gt;
&lt;DIV class="css-175oi2r r-1adg3ll r-1udh08x"&gt;
&lt;DIV class="r-1p0dtai r-1pi2tsx r-u8s1d r-1d2f490 r-ipm5af r-13qz1uu"&gt;
&lt;DIV class="css-175oi2r r-1pi2tsx r-13qz1uu r-18u37iz"&gt;
&lt;DIV class="css-175oi2r r-1iusvr4 r-16y2uox r-eqz5dr"&gt;
&lt;DIV class="css-175oi2r r-1iusvr4 r-16y2uox r-bnwqim r-zl2h9q"&gt;
&lt;DIV id="tinyMceEditorOtakarKlier_3" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorOtakarKlier_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorOtakarKlier_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Screen shots in the original post on Twitter.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="css-175oi2r r-1iusvr4 r-16y2uox r-bnwqim"&gt;
&lt;DIV class="css-175oi2r r-16y2uox r-1pi2tsx r-13qz1uu"&gt;
&lt;DIV class="css-175oi2r r-1p0dtai r-1d2f490 r-1udh08x r-u8s1d r-zchlnj r-ipm5af"&gt;
&lt;DIV class="css-175oi2r r-1mlwlqe r-1udh08x r-417010" aria-label="Image" data-testid="tweetPhoto"&gt;
&lt;DIV id="tinyMceEditorOtakarKlier_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Also PAN has updated their guidance and a search for compromise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://security.paloaltonetworks.com/CVE-2024-3400#:~:text=Q.Are%20there%20any%20checks%20I%20can%20run%20on%20my%20device%20to%20look%20for%20evidence%20of%20attempted%20exploit%20activity%3F" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2024-3400#:~:text=Q.Are%20there%20any%20checks%20I%20can%20run%20on%20my%20device%20to%20look%20for%20evidence%20of%20attempted%20exploit%20activity%3F&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good luck to all!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 19 Apr 2024 14:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2024-3400-ioc-s/m-p/584343#M116721</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-04-19T14:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2024-3400 IOC's</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2024-3400-ioc-s/m-p/584578#M116763</link>
      <description>&lt;P&gt;Thanks for sharing&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 00:56:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2024-3400-ioc-s/m-p/584578#M116763</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-04-23T00:56:36Z</dc:date>
    </item>
  </channel>
</rss>

