<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Advice blocking URl/ZIP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36236#M26647</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are receiving the same emails,which last 28/11/14, infected our system with cryptoloker. These links come from different domains but have in common the following url&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://xxxxxxxx.xx/Billing/invoice.zip" rel="nofollow"&gt;http://xxxxxxxx.xx/Billing/invoice.zip&lt;/A&gt;&lt;SPAN&gt;. How could we avoid that if someone clicks the link, not end infecting our systems? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any advice?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Dec 2014 08:31:41 GMT</pubDate>
    <dc:creator>SOC_CSG</dc:creator>
    <dc:date>2014-12-10T08:31:41Z</dc:date>
    <item>
      <title>Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36236#M26647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are receiving the same emails,which last 28/11/14, infected our system with cryptoloker. These links come from different domains but have in common the following url&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://xxxxxxxx.xx/Billing/invoice.zip" rel="nofollow"&gt;http://xxxxxxxx.xx/Billing/invoice.zip&lt;/A&gt;&lt;SPAN&gt;. How could we avoid that if someone clicks the link, not end infecting our systems? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any advice?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2014 08:31:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36236#M26647</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-12-10T08:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36237#M26648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello COS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do You have av/threat/WildFire protection applied on security rules that passing traffic to internet?&lt;/P&gt;&lt;P&gt;Have You latest updates applied? Cryptolocker is well known malware (but it's still changing its code). Did You create a&amp;nbsp; support case for this false positive?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my opinion You have to create data filtering if the filename is always "invoice.zip" I try to find examples in archiwum but I didn't find any examples how to get it.&lt;/P&gt;&lt;P&gt;I hope that someone give You examples.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2014 08:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36237#M26648</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-12-10T08:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36238#M26649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we have only URL filtering license. We have updated the virus/threats signatures. We have thought add in block list (URL filtering profile) this line */invoce.zip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it would work? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2014 08:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36238#M26649</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-12-10T08:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36239#M26650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did You read:&lt;/P&gt;&lt;P&gt;&lt;A href="http://researchcenter.paloaltonetworks.com/2014/07/banking-security-best-practices-zeus-cryptolocker/" title="http://researchcenter.paloaltonetworks.com/2014/07/banking-security-best-practices-zeus-cryptolocker/"&gt;http://researchcenter.paloaltonetworks.com/2014/07/banking-security-best-practices-zeus-cryptolocker/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://researchcenter.paloaltonetworks.com/2013/11/palo-alto-networks-can-stop-cryptolocker/" title="http://researchcenter.paloaltonetworks.com/2013/11/palo-alto-networks-can-stop-cryptolocker/"&gt;http://researchcenter.paloaltonetworks.com/2013/11/palo-alto-networks-can-stop-cryptolocker/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please follow this documents carefully, Cryptolocker isnt a "simple" malware, so without additional licences I think that i will be hard to detect and stop them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2014 09:10:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36239#M26650</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-12-10T09:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36240#M26651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;which license is necessary to use FILE BLOCKING???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have only URL FILTERING and THREAT PREVENTION licenses. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2014 09:14:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36240#M26651</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-12-10T09:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36241#M26652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to &lt;A href="https://www.paloaltonetworks.com/products/features/data-filtering.html" title="https://www.paloaltonetworks.com/products/features/data-filtering.html"&gt;Data Filtering and File Blocking - Palo Alto Networks&lt;/A&gt; and my understanding it using THREAT PREVENTION licenses&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2014 10:35:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36241#M26652</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-12-10T10:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36242#M26653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using a spam filter? May be blocking the incoming emails filtering by attachment or content may be a quicker solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or create a data filtering profile for file type .zip, direction = download, with regex to match invoice.zip, and then apply it to your security policies. Note: I haven't tested this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Larry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2014 18:23:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36242#M26653</guid>
      <dc:creator>hvcomputech</dc:creator>
      <dc:date>2014-12-10T18:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36243#M26654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yet another option to help you prevent further infections...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://xxxxxxxx.xx/Billing/invoice.zip" rel="nofollow" style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #006595;"&gt;http://xxxxxxxx.xx&lt;/A&gt; is most likely a shady domain.&lt;/P&gt;&lt;P&gt;You can respond the DNS Query with a Honeypot IP and do DNS Sinkhole, thus preventing the infection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="loading" href="https://live.paloaltonetworks.com/docs/DOC-6220" style="font-size: 10pt; line-height: 1.5em;" title="https://live.paloaltonetworks.com/docs/DOC-6220"&gt;https://live.paloaltonetworks.com/docs/DOC-6220&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2014 01:22:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36243#M26654</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2014-12-11T01:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36244#M26655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is the mail sender and the name of&amp;nbsp; attached file within changes, this happened several weeks ago and I created a rule tu deny the source, but now the source is different and also the file name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So data-filtering to deny incoming zip files with the regex "invoice.zip" won't be usefull in the future, and redirect the web page to a honeypot or sinkhole has the same problem, it changes in time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I read the post from &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Slawek and could be usefull. I will kept you inform.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;Gonzalo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2014 07:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36244#M26655</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-12-11T07:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Advice blocking URl/ZIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36245#M26656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two more docs:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-7162"&gt;Ensuring Optimum Protection for CryptoLocker and P2PZeus (GameOverZeus)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6628"&gt;How to Deal with Conficker using DNS Sinkhole&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that will be helpfull for You&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2014 12:10:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advice-blocking-url-zip/m-p/36245#M26656</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-12-11T12:10:28Z</dc:date>
    </item>
  </channel>
</rss>

