<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regin detection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18362#M13392</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find more information here &lt;A href="https://live.paloaltonetworks.com/docs/DOC-8408"&gt;Regin Malware (regin.backdoor)&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Nov 2014 20:14:59 GMT</pubDate>
    <dc:creator>gbogojevic</dc:creator>
    <dc:date>2014-11-26T20:14:59Z</dc:date>
    <item>
      <title>Regin detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18361#M13391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that this bit of spyware is not well understood as to it's ultimate purpose, very hard to detect and in fact, with the media converge it has had recently I am sure whoever coded this nasty has since changed it's code/behavior. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But my question is, does or is PA able to detect any such traffic from this malicious code given that it has taken the "Security experts" years to come back with their prognosis on the code in the first place. Or is this one of those things that we just have to pray to the IT deities that we never fall under the gaze of someone who is wielding such a powerful bit of spyware?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Nov 2014 17:01:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18361#M13391</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2014-11-26T17:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: Regin detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18362#M13392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find more information here &lt;A href="https://live.paloaltonetworks.com/docs/DOC-8408"&gt;Regin Malware (regin.backdoor)&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Nov 2014 20:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18362#M13392</guid>
      <dc:creator>gbogojevic</dc:creator>
      <dc:date>2014-11-26T20:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Regin detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18363#M13393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i would be interested in this as well...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No access to the link you provided though......even though i am logged in..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Nov 2014 22:24:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18363#M13393</guid>
      <dc:creator>paul.stinson</dc:creator>
      <dc:date>2014-11-26T22:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Regin detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18364#M13394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the link. Although I am getting "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; background-color: #f3e1dd;"&gt;Access to this place or content is restricted"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you provide a working link please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 10:51:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18364#M13394</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2014-11-27T10:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Regin detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18365#M13395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am unable to get to the link also&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Nov 2014 11:09:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18365#M13395</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2014-11-27T11:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Regin detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18366#M13396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone have any further information on this? It seems a few people would be interested in knowing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Nov 2014 11:03:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18366#M13396</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2014-11-28T11:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Regin detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18367#M13397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I'm sorry to say, after doing a little research it looks like you are out of luck for now.&amp;nbsp; Researchers have yet to say how victims get infected but that the malware disguises itself as legitimate Microsoft Software. I suggest you make sure your environment is as clean as possible to cover any other exploit that may have been used to deliver it.&amp;nbsp; IE. updated OS/software, updated sigs, etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Edit:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Here is Symantec's whitepaper on the malware, they were the ones to discover it:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;A href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/regin-analysis.pdf" title="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/regin-analysis.pdf"&gt;http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/regin-analysis.pdf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;They have been unable to reproduce infection but through investigation and logs they say it can be delivered through spoofed websites and such.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Nov 2014 13:22:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18367#M13397</guid>
      <dc:creator>Dz3015</dc:creator>
      <dc:date>2014-11-28T13:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Regin detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18368#M13398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for coming back DZ&lt;/P&gt;&lt;P&gt;We use WSUS to deliver any MS updates/installs that we do. So hopefully it will help protect us to a degree.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is just strange that there is not a lot of noise being kicked up about this by AV companies. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Nov 2014 14:56:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18368#M13398</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2014-11-28T14:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Regin detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18369#M13399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem!&amp;nbsp; The discovery of it is still less that a week old and given that it appears to be a well funded nation-state created malware it may take some time to fully investigate before they can release anything on a signature level to block it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Nov 2014 15:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/regin-detection/m-p/18369#M13399</guid>
      <dc:creator>Dz3015</dc:creator>
      <dc:date>2014-11-28T15:06:50Z</dc:date>
    </item>
  </channel>
</rss>

