<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Eicar and Palo Alto threat-db in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50822#M37396</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Response to your Observation : I had to visit Threat Vault and search for the ID: &lt;A class="jive-link-external-small" href="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2069593" style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #316989; background-color: #ffffff;"&gt;2069593&lt;/A&gt; the first time and now it opens up every single time.&lt;/P&gt;&lt;P&gt;I could add Threat Exception which validates that Threat ID for 100000&lt;/P&gt;&lt;P&gt;&lt;IMG alt="EicarTestFile.PNG" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/5795_EicarTestFile.PNG" style="width: 450px; height: 269px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Mar 2013 00:11:50 GMT</pubDate>
    <dc:creator>UhMayYeah</dc:creator>
    <dc:date>2013-03-01T00:11:50Z</dc:date>
    <item>
      <title>Eicar and Palo Alto threat-db</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50820#M37394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First a question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where and how can I see what is the default action for a particular threat, vuln or spyware threatid?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Preferly from within the box itself...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And now for an observation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried searching for eicar in the threat vault and obviously there are four different (?) eicars registered:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2739329 Virus/Win32.eicar-av-test.b&lt;/P&gt;&lt;P&gt;2459563 Virus/DOS.eicar_test_file.j&lt;/P&gt;&lt;P&gt;2101399 Virus/Win32.eicartestfile.e&lt;/P&gt;&lt;P&gt;2069593 Virus/Win32.eicartestfile.bh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first three can be opened:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2739329" title="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2739329"&gt;https://threatvault.paloaltonetworks.com/Home/VirusDetail/2739329&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2459563" title="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2459563"&gt;https://threatvault.paloaltonetworks.com/Home/VirusDetail/2459563&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2101399" title="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2101399"&gt;https://threatvault.paloaltonetworks.com/Home/VirusDetail/2101399&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the fourth just wont load when clicking on it the the results:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2069593" title="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2069593"&gt;https://threatvault.paloaltonetworks.com/Home/VirusDetail/2069593&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however the url (when written manually in the address field) works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And now for the added feature:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All four reports that they where added in content-db v960 (2013-02-28) !?!?!?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Content Release&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 960 (2/28/2013) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And... looking at each page it clearly looks like output from wildfire... but the true eicar testfile wont try to change netsh.exe settings, dump exe files, alter register keys etc... or did I miss what eicar testfile is supposed to do? :smileysilly:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.eicar.org/85-0-Download.html" title="http://www.eicar.org/85-0-Download.html"&gt;Download ° EICAR - European Expert Group for IT-Security &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also as a sidenote the threatid for the true eicar testfile seems to be threatid 100000, but this threatid cannot be located in the threat vault!?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2013 22:30:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50820#M37394</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-02-28T22:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Eicar and Palo Alto threat-db</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50821#M37395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;First&amp;nbsp; Answer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Where and how can I see what is the default action for a particular threat, vuln or spyware threatid?&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;IMG alt="See Default Action.PNG" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/5790_See Default Action.PNG" style="width: 450px; height: 265px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 00:05:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50821#M37395</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-03-01T00:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Eicar and Palo Alto threat-db</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50822#M37396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Response to your Observation : I had to visit Threat Vault and search for the ID: &lt;A class="jive-link-external-small" href="https://threatvault.paloaltonetworks.com/Home/VirusDetail/2069593" style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #316989; background-color: #ffffff;"&gt;2069593&lt;/A&gt; the first time and now it opens up every single time.&lt;/P&gt;&lt;P&gt;I could add Threat Exception which validates that Threat ID for 100000&lt;/P&gt;&lt;P&gt;&lt;IMG alt="EicarTestFile.PNG" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/5795_EicarTestFile.PNG" style="width: 450px; height: 269px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 00:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50822#M37396</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-03-01T00:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Eicar and Palo Alto threat-db</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50823#M37397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ohh... I guess I missed that checkbox in the lower left &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I assume that AV signatures doesnt have any default action or such attached to them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding Eicar I was more thinking of why there are four of them and why threatid 100000 isnt searchable through the threat vault webpage?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 07:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50823#M37397</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-01T07:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Eicar and Palo Alto threat-db</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50824#M37398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just tried to open each of those links to the Threat Vault in the original post, and I had to close the tabs and open them a second time for them to work (on each individual link)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that some sort of web session or cookie or whatever gets established the fist time the link is visited, but the page doesn't display the first time. When you hit the link for the second time the actual page displays. Sounds like a session thing to me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 15:43:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/eicar-and-palo-alto-threat-db/m-p/50824#M37398</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-03-01T15:43:32Z</dc:date>
    </item>
  </channel>
</rss>

