<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MacDefender Signature in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/macdefender-signature/m-p/39725#M29138</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿﻿﻿Has anyone seen a lot of activity around the MacDefender Command and Control Traffic (event ID 13104 and 13108)&amp;nbsp; spyware threat since the introduction of these signatures? I believe first add of these signatures was 248-993 and then updated in 249-1005.&amp;nbsp; I am trying to get a handle on the numerous daily "blocked" events we are seeing for these connections.&amp;nbsp; According to what I know of this malicious behavior - the payload is against the Mac OS only.&amp;nbsp; However, we have no Macs.&amp;nbsp; All these events are happening to PCs.&amp;nbsp; Is it perhaps because a drive-by or web link is bringing our users to the known bad external IPs? Also want to validate that this is indeed a real event and not a false positive - for we are seeing about a dozen of these events a day - never to same internal user.&amp;nbsp; Curious if anyone is seeing any of this activity and thoughts before I open a case. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Jun 2011 21:18:09 GMT</pubDate>
    <dc:creator>MGoodnow</dc:creator>
    <dc:date>2011-06-01T21:18:09Z</dc:date>
    <item>
      <title>MacDefender Signature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/macdefender-signature/m-p/39725#M29138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿﻿﻿Has anyone seen a lot of activity around the MacDefender Command and Control Traffic (event ID 13104 and 13108)&amp;nbsp; spyware threat since the introduction of these signatures? I believe first add of these signatures was 248-993 and then updated in 249-1005.&amp;nbsp; I am trying to get a handle on the numerous daily "blocked" events we are seeing for these connections.&amp;nbsp; According to what I know of this malicious behavior - the payload is against the Mac OS only.&amp;nbsp; However, we have no Macs.&amp;nbsp; All these events are happening to PCs.&amp;nbsp; Is it perhaps because a drive-by or web link is bringing our users to the known bad external IPs? Also want to validate that this is indeed a real event and not a false positive - for we are seeing about a dozen of these events a day - never to same internal user.&amp;nbsp; Curious if anyone is seeing any of this activity and thoughts before I open a case. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 21:18:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/macdefender-signature/m-p/39725#M29138</guid>
      <dc:creator>MGoodnow</dc:creator>
      <dc:date>2011-06-01T21:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: MacDefender Signature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/macdefender-signature/m-p/39726#M29139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A couple of cases came into Support regarding the MAC Defender but both are waiting on the customer to provide a pcap of the traffic so nothing conclusive yet.&amp;nbsp; If you can provide a pcap, please go ahead and open a case so that engineering can determine if it is a false positive or not.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 15:35:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/macdefender-signature/m-p/39726#M29139</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2011-06-06T15:35:40Z</dc:date>
    </item>
  </channel>
</rss>

