<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spyware Infect Host report from P.A. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188162#M57154</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76373"&gt;@wrainwater&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm going to agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;on this one, unless you suspect that this was abnormal and hasn't always been present it's likely nothing to worry about. That being said if this is the first time that you've encountered these alerts, it would be something that I would look into further.&amp;nbsp;&lt;/P&gt;&lt;P&gt;More information from PA can be found&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/Understanding-HTTP-Evasion-Detection-Signatures/ta-p/79218" target="_blank"&gt;HERE&lt;/A&gt;, which does a fairly good job explaining&amp;nbsp;relevant threats and why it might be present. You can also search threatvault for 14978. I really wouldn't be too worried about it, unless it has only just started to show up recently and you haven't been getting the alerts prior.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2017 14:57:12 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-11-21T14:57:12Z</dc:date>
    <item>
      <title>Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/187956#M57118</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I just got a spyware infected host report that says something like&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Destination address&amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; Destination Host Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|&amp;nbsp; &amp;nbsp;Count&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;X.X.X.X&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; hostname.domain.com&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2.94k&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;X.X.X.X&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; hostname2.domain.com&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.44k&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;X.X.X.X&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; hostname3.domain.com&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 681&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;Some of the hostnames are pretty important servers, so this has me worried about. Can anyone tell me what the report is telling me? Are these servers infect with spyware and the spyware is sending that much data out?&amp;nbsp;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 13:45:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/187956#M57118</guid>
      <dc:creator>wrainwater</dc:creator>
      <dc:date>2017-11-20T13:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/187995#M57122</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76373"&gt;@wrainwater&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Additional information would be helpful. Are these servers actually your internal servers, or external servers that your users are accessing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you access your Threat logs and filter on ( subtype eq spyware) you'll be able to see the logs for what is triggering this report. What exactly is being picked up on this report?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 15:46:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/187995#M57122</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-20T15:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188135#M57147</link>
      <description>&lt;P&gt;they are internal servers. a few domain controllers, one front end exchange server, and a few others.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 13:46:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188135#M57147</guid>
      <dc:creator>wrainwater</dc:creator>
      <dc:date>2017-11-21T13:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188137#M57148</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76373"&gt;@wrainwater&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;At that point you'd have to look at what the Threat database actually has listed for these servers. If you can post what the common threats are we can actually take a look at it with you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 13:49:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188137#M57148</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-21T13:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188139#M57149</link>
      <description>&lt;P&gt;Im assuming you are referring to monitor - logs - threat and use the servers ip address to see what it is telling me right?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 13:53:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188139#M57149</guid>
      <dc:creator>wrainwater</dc:creator>
      <dc:date>2017-11-21T13:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188145#M57152</link>
      <description>&lt;P&gt;Nevermind, I figured out what you meant. here is a screenshot&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="spyware.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12550i48A65C9600FF9767/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="spyware.JPG" alt="spyware.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 14:00:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188145#M57152</guid>
      <dc:creator>wrainwater</dc:creator>
      <dc:date>2017-11-21T14:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188161#M57153</link>
      <description>&lt;P&gt;Looks like noise...&amp;nbsp; Varied and non-associated dest URLs.&amp;nbsp; Given the vuln name looks like a "caution" kinda alert.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 14:50:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188161#M57153</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-11-21T14:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188162#M57154</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76373"&gt;@wrainwater&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm going to agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;on this one, unless you suspect that this was abnormal and hasn't always been present it's likely nothing to worry about. That being said if this is the first time that you've encountered these alerts, it would be something that I would look into further.&amp;nbsp;&lt;/P&gt;&lt;P&gt;More information from PA can be found&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/Understanding-HTTP-Evasion-Detection-Signatures/ta-p/79218" target="_blank"&gt;HERE&lt;/A&gt;, which does a fairly good job explaining&amp;nbsp;relevant threats and why it might be present. You can also search threatvault for 14978. I really wouldn't be too worried about it, unless it has only just started to show up recently and you haven't been getting the alerts prior.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 14:57:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188162#M57154</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-21T14:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188163#M57155</link>
      <description>&lt;P&gt;Further if you look at the alert details:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Severity&lt;/TD&gt;&lt;TD&gt;informational&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Action&lt;/TD&gt;&lt;TD&gt;allow&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's either a "false positive" or the flag is legitimate and the firewall is highlighting a vulnerability of TLS likely flagging on a lower version of TLS.&amp;nbsp; Merely attempting to point out something COULD be exploited, not necessarily something which is ACTIVELY being exploited.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 15:10:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188163#M57155</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-11-21T15:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188180#M57156</link>
      <description>&lt;P&gt;Just to add to the conversation-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we do SSL decryption and always have hundreds to thousands of these alerts a day.&amp;nbsp; We've always had them, and I just ignore them because they are never an active threat, more informantive in nature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In spite of all of this, I still get a twinge of concern when I see them populate my logs.&amp;nbsp; I want to react to them because I see so many listed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security-minded brain and all.&amp;nbsp; LOL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dannon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 15:50:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188180#M57156</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2017-11-21T15:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware Infect Host report from P.A.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188181#M57157</link>
      <description>&lt;P&gt;thanks to all of you. Im actually in the process of setting up SSL decryption right now. I have a rule set up on my computer to decrypt all the outbound traffic. Once that is set up, it'll give me better info on what the SSL traffic really is.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 16:00:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/spyware-infect-host-report-from-p-a/m-p/188181#M57157</guid>
      <dc:creator>wrainwater</dc:creator>
      <dc:date>2017-11-21T16:00:17Z</dc:date>
    </item>
  </channel>
</rss>

