<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: JS/Trojan.iframe virus? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34092#M25003</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&amp;nbsp; Good information.&amp;nbsp; However, in this case it appears to be false positive triggered by the following (imenu?) code.&amp;nbsp;&amp;nbsp; No longer triggering after removal of this section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 1.5in;"&gt;&lt;SPAN style="color: #1f497d;"&gt;// ---- IM Code + Security [7.4 KB] ----&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 1.5in;"&gt;&lt;SPAN style="color: #1f497d;"&gt;im_version="10.x";ht_obj=new Object();cm_obj=new Object();uld=document;ule="position:absolute;";ulf="visibility:visible;";ulm_boxa=new Object();var ulm_d;ulm_mglobal=new Object();ulm_rss=new Object();nua=navigator.userAgent;ulm_ie=window.showHelp;ulm_ie7=nua.indexOf("MSIE 7")+1;ulm_mac=nua.indexOf("Mac")+1;ulm_navigator=nua.indexOf("Netscape")+1;ulm_version=parseFloat(navigator.vendorSub);ulm_oldnav=ulm_navigator&amp;amp;&amp;amp;ulm_version&amp;lt;7.1;ulm_oldie=ulm_ie&amp;amp;&amp;amp;nua.indexOf("MSIE 5.0")+1;ulm_iemac=ulm_ie&amp;amp;&amp;amp;ulm_mac;ulm_opera=nua.indexOf("Opera")+1;ulm_safari=nua.indexOf("afari")+1;x42="_";ulm_curs="cursor:hand;";if(!ulm_ie){x42="z";ulm_curs="cursor:pointer;";}ulmpi=window.imenus_add_pointer_image;var x43;for(mi=0;mi&amp;lt;(x1=uld.getElementsByTagName("UL")).length;mi++){if((x2=x1[mi].id)&amp;amp;&amp;amp;x2.indexOf("imenus")+1){dto=new window["imenus_data"+(x2=x2.substring(6))];ulm_boxa.dto=dto;ulm_boxa["dto"+x2]=dto;ulm_d=dto.menu_showhide_delay;if(ulm_ie&amp;amp;&amp;amp;!ulm_ie7&amp;amp;&amp;amp;!ulm_mac&amp;amp;&amp;amp;(b=window.imenus_efix))b(.......&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Dec 2012 19:25:59 GMT</pubDate>
    <dc:creator>schaleg2</dc:creator>
    <dc:date>2012-12-05T19:25:59Z</dc:date>
    <item>
      <title>JS/Trojan.iframe virus?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34087#M24998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seen hits for the &lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: black;"&gt;JS/Trojan.iframe virus&lt;/SPAN&gt; only since last Wednesday or Thursday.&amp;nbsp; Have seen them associated with three different websites.&amp;nbsp; I suspect false positives.&amp;nbsp; Anyone else out there just started seeing these?&amp;nbsp; Was the virus definition modified last week?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Eric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 18:55:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34087#M24998</guid>
      <dc:creator>schaleg2</dc:creator>
      <dc:date>2012-12-04T18:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.iframe virus?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34088#M24999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Specifically, it's identifying as &lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;JS/Trojan.iframe.esw.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 18:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34088#M24999</guid>
      <dc:creator>schaleg2</dc:creator>
      <dc:date>2012-12-04T18:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.iframe virus?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34089#M25000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have seen some hits on this.&amp;nbsp; Not too many.&amp;nbsp; 7 Unique Attacker IPs in the last 7 days.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 19:05:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34089#M25000</guid>
      <dc:creator>MGoodnow</dc:creator>
      <dc:date>2012-12-04T19:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.iframe virus?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34090#M25001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Strange because all mine have started occurring only since the morning of 11/29.&amp;nbsp; But since I'm blocking, one of them is impacting legitimate website access and the site owner doesn't see anything wrong on their side.&amp;nbsp; As far as I can tell, there is no way to create a virus exception for just a single URL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 22:52:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34090#M25001</guid>
      <dc:creator>schaleg2</dc:creator>
      <dc:date>2012-12-04T22:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.iframe virus?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34091#M25002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding site owner doesnt see anything wrong on their side:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://seclists.org/fulldisclosure/2012/Nov/94" title="http://seclists.org/fulldisclosure/2012/Nov/94"&gt;http://seclists.org/fulldisclosure/2012/Nov/94&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="https://www.securelist.com/en/blog/208193935/New_64_bit_Linux_Rootkit_Doing_iFrame_Injections" title="https://www.securelist.com/en/blog/208193935/New_64_bit_Linux_Rootkit_Doing_iFrame_Injections"&gt;https://www.securelist.com/en/blog/208193935/New_64_bit_Linux_Rootkit_Doing_iFrame_Injections&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://blog.crowdstrike.com/2012/11/http-iframe-injecting-linux-rootkit.html" title="http://blog.crowdstrike.com/2012/11/http-iframe-injecting-linux-rootkit.html"&gt;CrowdStrike: HTTP iframe Injecting Linux Rootkit&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 06:51:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34091#M25002</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-12-05T06:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.iframe virus?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34092#M25003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&amp;nbsp; Good information.&amp;nbsp; However, in this case it appears to be false positive triggered by the following (imenu?) code.&amp;nbsp;&amp;nbsp; No longer triggering after removal of this section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 1.5in;"&gt;&lt;SPAN style="color: #1f497d;"&gt;// ---- IM Code + Security [7.4 KB] ----&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 1.5in;"&gt;&lt;SPAN style="color: #1f497d;"&gt;im_version="10.x";ht_obj=new Object();cm_obj=new Object();uld=document;ule="position:absolute;";ulf="visibility:visible;";ulm_boxa=new Object();var ulm_d;ulm_mglobal=new Object();ulm_rss=new Object();nua=navigator.userAgent;ulm_ie=window.showHelp;ulm_ie7=nua.indexOf("MSIE 7")+1;ulm_mac=nua.indexOf("Mac")+1;ulm_navigator=nua.indexOf("Netscape")+1;ulm_version=parseFloat(navigator.vendorSub);ulm_oldnav=ulm_navigator&amp;amp;&amp;amp;ulm_version&amp;lt;7.1;ulm_oldie=ulm_ie&amp;amp;&amp;amp;nua.indexOf("MSIE 5.0")+1;ulm_iemac=ulm_ie&amp;amp;&amp;amp;ulm_mac;ulm_opera=nua.indexOf("Opera")+1;ulm_safari=nua.indexOf("afari")+1;x42="_";ulm_curs="cursor:hand;";if(!ulm_ie){x42="z";ulm_curs="cursor:pointer;";}ulmpi=window.imenus_add_pointer_image;var x43;for(mi=0;mi&amp;lt;(x1=uld.getElementsByTagName("UL")).length;mi++){if((x2=x1[mi].id)&amp;amp;&amp;amp;x2.indexOf("imenus")+1){dto=new window["imenus_data"+(x2=x2.substring(6))];ulm_boxa.dto=dto;ulm_boxa["dto"+x2]=dto;ulm_d=dto.menu_showhide_delay;if(ulm_ie&amp;amp;&amp;amp;!ulm_ie7&amp;amp;&amp;amp;!ulm_mac&amp;amp;&amp;amp;(b=window.imenus_efix))b(.......&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 19:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34092#M25003</guid>
      <dc:creator>schaleg2</dc:creator>
      <dc:date>2012-12-05T19:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.iframe virus?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34093#M25004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with the premise this may be a false positive.&amp;nbsp; It is far too common and started showing up for me on the 30th as well.&amp;nbsp; It is coming from benign sites that get traveled to frequently by our users, yet an enormous amount of effort into located the infection has not been fruitful.&amp;nbsp; We have found exactly nothing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2012 13:02:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34093#M25004</guid>
      <dc:creator>lchildress</dc:creator>
      <dc:date>2012-12-07T13:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: JS/Trojan.iframe virus?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34094#M25005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm seeing the same thing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 20:55:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/js-trojan-iframe-virus/m-p/34094#M25005</guid>
      <dc:creator>tfigueroa</dc:creator>
      <dc:date>2012-12-10T20:55:12Z</dc:date>
    </item>
  </channel>
</rss>

