<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: JS/Trojan.redirector.cay false postive? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28456#M20785</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was seeing the exact same problems.&amp;nbsp; Multiple blocks of JS/Trojan.redirector.cay as threat, and atdmt.com and doubleclick.net are blocked as malware-sites.&amp;nbsp; Google Maps and Mapquest will not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I received an email that it was indeed a false positive on JS/Trojan.redirector.cay and that it would be corrected in the next update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Feb 2012 16:56:01 GMT</pubDate>
    <dc:creator>mlane</dc:creator>
    <dc:date>2012-02-22T16:56:01Z</dc:date>
    <item>
      <title>JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28451#M20780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Starting from what appears to be right after pattern update 683-936 was committed - we began receiving a very substantial amount of alerts from multiple internal "victims" for this Trojan.&amp;nbsp; I am still investigating this internally.&amp;nbsp; Has anyone else had a large amount of activity on this signature starting recently? Looking to verify if this is a false positive or not.&amp;nbsp; Other AV protection layers are not reporting this type of activity.&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE align="center" cellpadding="5" style="widows:2;text-transform:none;background-color:#ebedee;font-family:Tahoma, Arial, Helvetica, sans-serif;orphans:2;letter-spacing:normal;-webkit-text-size-adjust:auto" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH align="right" style="border-bottom:#dbdbdb 1px solid;text-align:left;padding-bottom:3px;background-color:#ffffff;font-style:normal;padding-left:4px;background-attachment:scroll;padding-right:4px;font-family:Tahoma, Arial, Helvetica, sans-serif;background-position:0% 0%;color:#798993;font-size:10px;font-weight:bold;padding-top:3px"&gt;Name:&lt;/TH&gt;&lt;TD style="font-family:Tahoma, Arial, Helvetica, sans-serif;font-size:11px"&gt;JS/Trojan.redirector.cay&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TH align="right" style="border-bottom:#dbdbdb 1px solid;text-align:left;padding-bottom:3px;background-color:#ffffff;font-style:normal;padding-left:4px;background-attachment:scroll;padding-right:4px;font-family:Tahoma, Arial, Helvetica, sans-serif;background-position:0% 0%;color:#798993;font-size:10px;font-weight:bold;padding-top:3px"&gt;ID:&lt;/TH&gt;&lt;TD style="font-family:Tahoma, Arial, Helvetica, sans-serif;font-size:11px"&gt;250007&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TH align="right" style="border-bottom:#dbdbdb 1px solid;text-align:left;padding-bottom:3px;background-color:#ffffff;font-style:normal;padding-left:4px;background-attachment:scroll;padding-right:4px;font-family:Tahoma, Arial, Helvetica, sans-serif;background-position:0% 0%;color:#798993;font-size:10px;font-weight:bold;padding-top:3px"&gt;Severity:&lt;/TH&gt;&lt;TD style="font-family:Tahoma, Arial, Helvetica, sans-serif;font-size:11px"&gt;&lt;IMG src="https://ip1.i.lithium.com/063a6a18360069bb5eac8ea5c1d76b6e36e09770/68747470733a2f2f746f72696e6f2f696d616765732f7468726561745f6d656469756d2e676966" /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TH align="right" style="border-bottom:#dbdbdb 1px solid;text-align:left;padding-bottom:3px;background-color:#ffffff;font-style:normal;padding-left:4px;background-attachment:scroll;padding-right:4px;font-family:Tahoma, Arial, Helvetica, sans-serif;background-position:0% 0%;color:#798993;font-size:10px;font-weight:bold;padding-top:3px" valign="top"&gt;Description:&lt;/TH&gt;&lt;TD style="font-family:Tahoma, Arial, Helvetica, sans-serif;font-size:11px"&gt;This signature detected JS/Trojan.redirector.cay&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 18:06:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28451#M20780</guid>
      <dc:creator>MGoodnow</dc:creator>
      <dc:date>2012-02-21T18:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28452#M20781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am seeing this as well.&amp;nbsp; I thought maybe it was a single website, but from the looks of it, I think it just may be a false positive.&amp;nbsp; I have identified the source IP's as being owned by a company called AppNexus (at least this is our case).&amp;nbsp; I'm still investigating myself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 19:44:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28452#M20781</guid>
      <dc:creator>mmorfoot</dc:creator>
      <dc:date>2012-02-21T19:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28453#M20782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the update from your end as well.&amp;nbsp; I updated to the latest version a few minutes ago and no change.&amp;nbsp; Events still showing up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" id="TableGeneralInformation" style="border-bottom:#c1c7cb 1px solid;border-left:#c1c7cb 1px solid;widows:2;text-transform:none;background-color:#eff1f2;font-family:Arial, sans-serif;orphans:2;letter-spacing:normal;border-top:#c1c7cb 1px solid;border-right:#c1c7cb 1px solid;-webkit-text-size-adjust:auto" width="340"&gt;&lt;TBODY id="BodyGeneralInformation"&gt;&lt;TR&gt;&lt;TD align="left" style="text-align:right;padding-bottom:3px;background-color:#ffffff;padding-left:4px;padding-right:4px;font-family:Tahoma, Arial, Helvetica, sans-serif;color:#5a6e7a;font-size:11px;vertical-align:top;padding-top:3px"&gt;Antivirus version&lt;/TD&gt;&lt;TD align="left" style="padding-bottom:3px;background-color:#ffffff;padding-left:4px;padding-right:4px;font-family:Tahoma, Arial, Helvetica, sans-serif;font-size:11px;vertical-align:top;padding-top:3px"&gt;684-937 (2012/02/20)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 20:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28453#M20782</guid>
      <dc:creator>MGoodnow</dc:creator>
      <dc:date>2012-02-21T20:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28454#M20783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We also have a lot of these. The ones I have examined are from adnxs.com, which appears to be an advertising site. Brightcloud categorizes it as Trustworthy.&lt;/P&gt;&lt;P&gt;We also seem to have URL filtering categorizing a lot of advertisers like atdmt.com and doubleclick.net as malware sites.&lt;/P&gt;&lt;P&gt;Neil Flanagan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 14:47:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28454#M20783</guid>
      <dc:creator>n.flanagan</dc:creator>
      <dc:date>2012-02-22T14:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28455#M20784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are also seeing a high number of these.&amp;nbsp; Have the latest and greatest defenitions as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 15:50:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28455#M20784</guid>
      <dc:creator>u10723</dc:creator>
      <dc:date>2012-02-22T15:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28456#M20785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was seeing the exact same problems.&amp;nbsp; Multiple blocks of JS/Trojan.redirector.cay as threat, and atdmt.com and doubleclick.net are blocked as malware-sites.&amp;nbsp; Google Maps and Mapquest will not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I received an email that it was indeed a false positive on JS/Trojan.redirector.cay and that it would be corrected in the next update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 16:56:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28456#M20785</guid>
      <dc:creator>mlane</dc:creator>
      <dc:date>2012-02-22T16:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28457#M20786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This signature is a confirmed false positive.&amp;nbsp; It has been removed for tomorrow's AV content release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 17:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28457#M20786</guid>
      <dc:creator>tettema</dc:creator>
      <dc:date>2012-02-22T17:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28458#M20787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to update the AV manually later. Can you provide which AV version have fixed this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Feb 2012 01:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28458#M20787</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-02-23T01:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28459#M20788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone can help to confirm which AV version have fixed the "JS/Trojan.redirector.cay false positive" issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have opened a tech support case with case no. 00066795 to get the AV version number. The funny thing is the engineer still asking me for pcap. If the signature is removed I cannot get packet capture based on threat id in threat logs. :smileyconfused:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Feb 2012 04:24:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28459#M20788</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-02-24T04:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.redirector.cay false postive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28460#M20789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Content version 686-XXX has the fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we get a report of a false positive we usually ask for the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show system info&lt;/P&gt;&lt;P&gt;-- To&amp;nbsp; see all currently installed software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Threat logs that you believe to be a false positive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic logs for the IP address identified in the Threat log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewall is configured to save a PCAP of the packet that triggered the threat we ask for this as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the threat was triggered by a URL or a file download, we would like this information to try and reproduce internally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Feb 2012 01:27:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-redirector-cay-false-postive/m-p/28460#M20789</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2012-02-25T01:27:55Z</dc:date>
    </item>
  </channel>
</rss>

