<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trojan dropper.bxzq detected and not in Threath Database in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trojan-dropper-bxzq-detected-and-not-in-threath-database/m-p/26637#M19447</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Samuel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As to your first question, it appears you are running 3.1 software release... the viruses for this release are not yet uploaded on our support site and as such you are not able to find that information. We are working on this and would post a note on knowledge point when this is done. Thanks for your patience,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As to your second question, the ID may not have been included in the "vulnerabilities" threat report as the report contains top 50 vulns only and depending upon whether the particular vulnerability made to the top 50 vulns, it may not have been included in the report. Did you have 50 vulnerabilities reported in the vulnerability threat report?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Sandeep &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Sep 2010 17:46:00 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2010-09-07T17:46:00Z</dc:date>
    <item>
      <title>Trojan dropper.bxzq detected and not in Threath Database</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trojan-dropper-bxzq-detected-and-not-in-threath-database/m-p/26636#M19446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, our Palo Alto has detected the threat:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="retro"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="retro" width="180"&gt;Name:&lt;/TD&gt;&lt;TD class="retro-value"&gt;Trojan/Win32.dropper.bxzq&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="retro" width="180"&gt;ID:&lt;/TD&gt;&lt;TD class="retro-value"&gt;2723653&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="retro"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="retro"&gt;Description:&lt;/TD&gt;&lt;TD class="retro-value"&gt;This signature detected Trojan/Win32.dropper.bxzq&amp;nbsp; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="retro"&gt;Severity:&lt;/TD&gt;&lt;TD class="retro-value"&gt;&lt;IMG border="0" src="https://ip1.i.lithium.com/da03ee348d596be50ca38578cec7ec368e9f5b77/68747470733a2f2f3137322e31382e312e3133332f696d616765732f7468726561745f6d656469756d2e676966" /&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if I try to find this threath by name or ID in Threat Database it doesn't exist, how is it possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the same time the Palo Alto has detected&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="retro"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="retro-value"&gt;MAIL: User Login Brute-force Attempt&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="retro" width="180"&gt;ID:&lt;/TD&gt;&lt;TD class="retro-value"&gt;40007&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="retro"&gt;Description:&lt;/TD&gt;&lt;TD class="retro-value"&gt;This event indicates that someone is using a brute force attack to gain&amp;nbsp; access to mail server through smtp/pop3/imap authentication request. &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="retro"&gt;Severity:&lt;/TD&gt;&lt;TD class="retro-value"&gt;&lt;IMG border="0" src="https://ip1.i.lithium.com/da03ee348d596be50ca38578cec7ec368e9f5b77/68747470733a2f2f3137322e31382e312e3133332f696d616765732f7468726561745f6d656469756d2e676966" /&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in Threat Reports, vulnerability it doesn't exist even though in Logs, Threat it appears like "vulnerability".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you explain this??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 11:25:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trojan-dropper-bxzq-detected-and-not-in-threath-database/m-p/26636#M19446</guid>
      <dc:creator>a.cadarso</dc:creator>
      <dc:date>2010-09-07T11:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan dropper.bxzq detected and not in Threath Database</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trojan-dropper-bxzq-detected-and-not-in-threath-database/m-p/26637#M19447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Samuel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As to your first question, it appears you are running 3.1 software release... the viruses for this release are not yet uploaded on our support site and as such you are not able to find that information. We are working on this and would post a note on knowledge point when this is done. Thanks for your patience,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As to your second question, the ID may not have been included in the "vulnerabilities" threat report as the report contains top 50 vulns only and depending upon whether the particular vulnerability made to the top 50 vulns, it may not have been included in the report. Did you have 50 vulnerabilities reported in the vulnerability threat report?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Sandeep &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 17:46:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trojan-dropper-bxzq-detected-and-not-in-threath-database/m-p/26637#M19447</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-09-07T17:46:00Z</dc:date>
    </item>
  </channel>
</rss>

