<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I've noticed an incomplate request to 111.111.111.111 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39178#M28731</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;using security profiles for related traffic will be fine to secure.&lt;/P&gt;&lt;P&gt;You Still need to clean the host with a tool.&lt;/P&gt;&lt;P&gt;There are many 3rd party freeware tools you can find on the web.from details you can also see the vendors&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/file/d2744a38a67fee26410d69d312d80d4802cc5112bfaedc50da8eb9ad7ee43fbe/analysis/" title="https://www.virustotal.com/en/file/d2744a38a67fee26410d69d312d80d4802cc5112bfaedc50da8eb9ad7ee43fbe/analysis/"&gt;https://www.virustotal.com/en/file/d2744a38a67fee26410d69d312d80d4802cc5112bfaedc50da8eb9ad7ee43fbe/analysis/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Nov 2014 10:06:13 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2014-11-03T10:06:13Z</dc:date>
    <item>
      <title>I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39171#M28724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;On PAN's Monitor tab i've noticed that one of our hosts(user's computers) send periodically some packets to 111.111.111.111 and receive any packets.on Application tab it stays incomplete!what is the shit?Did anyone have the problem like this?what can i do for figuring this out? any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Huge Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Tigran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 09:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39171#M28724</guid>
      <dc:creator>TigranGevorgyan</dc:creator>
      <dc:date>2014-11-03T09:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39172#M28725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tigran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Incomplete means that either the three way TCP handshake did NOT complete or the three way TCP handshake did complete but there was no data after the handshake to identify the application. In other words that traffic you are seeing is not really an application.&lt;/P&gt;&lt;P&gt;So to explain a little clearer, if a client sends a server a syn and the Palo Alto device creates a session for that syn, but the server never sends a SYN ACK in response back to the client, then that session would be seen as incomplete. More information can be found here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1549"&gt;Incomplete, Insufficient data and Not-applicable in the application field&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition , for example virustotal.com can provide you more information about specific IP address:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/ip-address/111.111.111.111/information/" title="https://www.virustotal.com/en/ip-address/111.111.111.111/information/"&gt;https://www.virustotal.com/en/ip-address/111.111.111.111/information/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 09:34:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39172#M28725</guid>
      <dc:creator>gbogojevic</dc:creator>
      <dc:date>2014-11-03T09:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39173#M28726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="22331" data-username="gbogojevic" href="https://live.paloaltonetworks.com/people/gbogojevic" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;gbogojevic&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for info. I've got all what you said to me, but i don't understand how can i sole this problem? maybe i should scan that computer for viruses?what do you think?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Huge Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tigran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 09:41:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39173#M28726</guid>
      <dc:creator>TigranGevorgyan</dc:creator>
      <dc:date>2014-11-03T09:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39174#M28727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There seems to be a malware on the host.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 09:42:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39174#M28727</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-11-03T09:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39175#M28728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tigran,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Yes, you should scan the local computer. In addition, you can apply security profile (antivirus, antispyware, vulnerability and URL profile)&amp;nbsp; to the security policy that matches traffic from that specific host.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 09:47:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39175#M28728</guid>
      <dc:creator>gbogojevic</dc:creator>
      <dc:date>2014-11-03T09:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39176#M28729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Panos,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I also think so. what kind of programs or ativiruses do you advise to use in such situations?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 09:49:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39176#M28729</guid>
      <dc:creator>TigranGevorgyan</dc:creator>
      <dc:date>2014-11-03T09:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39177#M28730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, Understood&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 09:51:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39177#M28730</guid>
      <dc:creator>TigranGevorgyan</dc:creator>
      <dc:date>2014-11-03T09:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39178#M28731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;using security profiles for related traffic will be fine to secure.&lt;/P&gt;&lt;P&gt;You Still need to clean the host with a tool.&lt;/P&gt;&lt;P&gt;There are many 3rd party freeware tools you can find on the web.from details you can also see the vendors&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/file/d2744a38a67fee26410d69d312d80d4802cc5112bfaedc50da8eb9ad7ee43fbe/analysis/" title="https://www.virustotal.com/en/file/d2744a38a67fee26410d69d312d80d4802cc5112bfaedc50da8eb9ad7ee43fbe/analysis/"&gt;https://www.virustotal.com/en/file/d2744a38a67fee26410d69d312d80d4802cc5112bfaedc50da8eb9ad7ee43fbe/analysis/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 10:06:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39178#M28731</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-11-03T10:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39179#M28732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Panos,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I've observed &lt;A class="loading" href="https://www.virustotal.com/en/file/d2744a38a67fee26410d69d312d80d4802cc5112bfaedc50da8eb9ad7ee43fbe/analysis/"&gt;https://www.virustotal.com/en/file/d2744a38a67fee26410d69d312d80d4802cc5112bfaedc50da8eb9ad7ee43fbe/analysis/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;this link and have a question.From Up come Antiviruses which Resulsts are in red colour, and then Antiviruses which results are in Green.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As i understand for example &lt;/P&gt;&lt;TABLE class="table table-striped" style="margin-bottom: 20px; color: #333333; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;&lt;TBODY&gt;&lt;TR style="border: 0px;"&gt;&lt;TD class="ltr" style="padding: 8px; border: 0px; background-color: #f9f9f9;"&gt;Ad-Aware&lt;/TD&gt;&lt;TD class="ltr text-red" style="padding: 8px; border: 0px; background-color: #f9f9f9; color: #b40c1a !important;"&gt;Gen:Trojan.Heur.GM.050005010A&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;This Antivirus can't fixed this&amp;nbsp; &lt;SPAN style="color: #b40c1a; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; background-color: #f9f9f9;"&gt;Gen:Trojan.Heur.GM.050005010A trojan virus.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #b40c1a; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; background-color: #f9f9f9;"&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;and Avast for example is up to date and can fix all viruses.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;am i right?I use Avast, hope it'll help.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Huge thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 12:28:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39179#M28732</guid>
      <dc:creator>TigranGevorgyan</dc:creator>
      <dc:date>2014-11-05T12:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39180#M28733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That was an example for a file which makes traffic to 111.111.111.111&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if it is green then it cannot detect that trojan&lt;/P&gt;&lt;P&gt;As you see top Detection ratio: 8 / 54&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 13:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39180#M28733</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-11-05T13:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39181#M28734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As i understand, i should use the one of the top 8 Antiviruses to detect that trojan, am i correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 13:13:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39181#M28734</guid>
      <dc:creator>TigranGevorgyan</dc:creator>
      <dc:date>2014-11-05T13:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39182#M28735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;for that malware and for that update version yes.Maybe with a new update others will also see that file.Or maybe it is a false positive.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 13:21:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39182#M28735</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-11-05T13:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: I've noticed an incomplate request to 111.111.111.111</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39183#M28736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 13:28:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-ve-noticed-an-incomplate-request-to-111-111-111-111/m-p/39183#M28736</guid>
      <dc:creator>TigranGevorgyan</dc:creator>
      <dc:date>2014-11-05T13:28:16Z</dc:date>
    </item>
  </channel>
</rss>

