<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: crilock.a (CRYPTOLOCKER HIJACK) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32238#M23642</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes Luis, Hope for the best.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Just an advice, can you make sure packet captures are enabled for the Antivirus Security Profile? It will take a packet capture of the threat, if affected by any virus ( i.e. &lt;SPAN class="GINGER_SOFATWARE_correct"&gt;crilock&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;.&lt;/SPAN&gt;a (CRYPTOLOCKER HIJACK) .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Have a nice day.!!!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Sep 2013 01:09:16 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2013-09-18T01:09:16Z</dc:date>
    <item>
      <title>crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32235#M23639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does any one knows if this has been detected and addresed by PAN, just trying to stay informed, could not find it in the latest virus definitios update&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis Cabrera&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Sep 2013 23:37:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32235#M23639</guid>
      <dc:creator>luisrolocq</dc:creator>
      <dc:date>2013-09-17T23:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32236#M23640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;A&lt;/SPAN&gt;&lt;SPAN style="font-family: Helvetica, sans-serif; color: #3b3b3b;"&gt;t this time, only antivirus signatures for PE viruses (&lt;/SPAN&gt;&lt;SPAN style="font-family: Helvetica, sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="GINGER_SOFATWARE_correct GINGER_SOFATWARE_noSuggestion"&gt;executables&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: Helvetica, sans-serif; color: #3b3b3b;"&gt;) are in the threat vault, aside from the vulnerability and anti-spyware signatures.&amp;nbsp; I have checked with www.virustotal.com, the virus information is available there. So, I would expect to be available with the PAN antivirus database as well. If PAN is unable to detect the virus through it, you can open a ticket with us and we will address into the next AV database. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Helvetica, sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Helvetica, sans-serif; color: #3b3b3b;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 00:42:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32236#M23640</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-18T00:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32237#M23641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replay, I checked vt.com as well and went throught the release notes for the lates av definitions on the PAN device, i could not mach the name that is why I posted here, just to make sure, at this point i guess we just have to hope for the best&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 00:56:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32237#M23641</guid>
      <dc:creator>luisrolocq</dc:creator>
      <dc:date>2013-09-18T00:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32238#M23642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes Luis, Hope for the best.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Just an advice, can you make sure packet captures are enabled for the Antivirus Security Profile? It will take a packet capture of the threat, if affected by any virus ( i.e. &lt;SPAN class="GINGER_SOFATWARE_correct"&gt;crilock&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;.&lt;/SPAN&gt;a (CRYPTOLOCKER HIJACK) .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Have a nice day.!!!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 01:09:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32238#M23642</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-18T01:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32239#M23643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is currently in the pipeline, we're working on covering this threat in the upcoming AV releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Aditi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 22:34:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32239#M23643</guid>
      <dc:creator>apasupulati</dc:creator>
      <dc:date>2013-09-18T22:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32240#M23644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this virus detected now?&lt;BR /&gt;What is the name of the signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jo Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 09:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32240#M23644</guid>
      <dc:creator>jochristian</dc:creator>
      <dc:date>2013-10-15T09:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32241#M23645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To answer my own question..&lt;/P&gt;&lt;P&gt;Seems like it's called: &lt;SPAN style="color: #222222; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ebedee;"&gt;Trojan-Ransom/Win32.blocker.shk&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jo Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 11:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32241#M23645</guid>
      <dc:creator>jochristian</dc:creator>
      <dc:date>2013-10-15T11:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32242#M23646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How do I confirm my PA is actively scanning traffic for this threat? I need to report this to my security team so they know we have safeguards in place for it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 19:42:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32242#M23646</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-11-18T19:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32243#M23647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mario,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Threat vault shows that we have 7 signatures for crilock - one of them is crilock.a&lt;/P&gt;&lt;P&gt;&lt;IMG alt="criclock.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9835_criclock.PNG.png" style="width: 620px; height: 298px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 19:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32243#M23647</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-18T19:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32244#M23648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kadak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick response! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; I've seen this in the vault. I am just wondering where I can see a list of these signatures on the firewall? Perhaps there is a release note showing these signatures listed so we we know they are covered? The current release notes for anti-virus 1147-1601 and 1146-1600 don't show these signatures listed (these are the current databases we have on our firewall).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 20:00:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32244#M23648</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-11-18T20:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: crilock.a (CRYPTOLOCKER HIJACK)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32245#M23649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I found what I am looking for. Clicking on the magnifying glass next to signature shows the release the signature was included in. This should work by comparing it to our current version. Thanks a ton!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 20:11:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crilock-a-cryptolocker-hijack/m-p/32245#M23649</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-11-18T20:11:44Z</dc:date>
    </item>
  </channel>
</rss>

