<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Enable WildFire to block jar file with 'malicious' Verdict in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/199548#M59124</link>
    <description>&lt;P&gt;Dear BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for your reply and theory for why the email was allowed despite being malicious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have captured the timestamps of the Wildfire evets here, in case that helps accurately diagnose the issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WildFire Summary 1.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13719iD2C9826B64CA4B6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="WildFire Summary 1.jpg" alt="WildFire Summary 1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P class="sectionTitle"&gt;WildFire Analysis Summary&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV class=" x-panel list-view"&gt;&lt;DIV class="x-panel-header x-unselectable"&gt;&lt;SPAN class="x-panel-header-text"&gt;File Information&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="x-panel-bwrap"&gt;&lt;DIV class="x-panel-body"&gt;&lt;DIV class="x-list-wrap"&gt;&lt;DIV class="x-list-body"&gt;&lt;DIV class="x-list-body-inner"&gt;&lt;EM&gt;File Type&lt;/EM&gt; &lt;EM&gt;JAVA JAR&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;File Signer&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;SHA-256&lt;/EM&gt; &lt;EM&gt;149862f4894c9dba2b21b507fa7bde835e6a6a44e35040331c5ab1de3ec4027d&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;SHA1&lt;/EM&gt; &lt;EM&gt;b8aed21b09bda3f02c54c53267ba696a1286e092&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;MD5&lt;/EM&gt; &lt;EM&gt;0ecacad6f88e1ddb859e881c1662b4a9&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;File Size&lt;/EM&gt; &lt;EM&gt;556535 bytes&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;First Seen Timestamp&lt;/EM&gt; &lt;EM&gt;2018-01-26 06:28:06 UTC&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;Verdict&lt;/EM&gt; &lt;EM&gt;&lt;STRONG&gt;malware&lt;/STRONG&gt;&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this information give more visibility to the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Feb 2018 09:37:04 GMT</pubDate>
    <dc:creator>Steve-Phillips</dc:creator>
    <dc:date>2018-02-08T09:37:04Z</dc:date>
    <item>
      <title>How to Enable WildFire to block jar file with 'malicious' Verdict</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/197798#M58773</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New to Palo Alto firewalls and new to this forum.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I please ask how I go about changing the Wildfire action on a jar file to block?&amp;nbsp; The action for this file has been to allow the file, despite the file being flagged as "malicious, as can be seen below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Wildfire jar.jpg" style="width: 793px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13481i1D86A27F5CEE1AB4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Wildfire jar.jpg" alt="Wildfire jar.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wish to change the action to "block", as is the case with the&amp;nbsp;"pe" files I can see in the Wildfire logs, as can be seen here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Wildfire logs.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13482i6A2B5F12D023BC55/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Wildfire logs.jpg" alt="Wildfire logs.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 09:34:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/197798#M58773</guid>
      <dc:creator>Steve-Phillips</dc:creator>
      <dc:date>2018-01-31T09:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to Enable WildFire to block jar file with 'malicious' Verdict</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/197953#M58796</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66688"&gt;@Steve-Phillips&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Within the Antivirus Security Profile that is assigned to the rule allowing the SMTP traffic to pass, you'll have to modify the 'WildFire Action' to reset-both instead of the default action of 'alert'. This article &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Enable-WildFire-to-Block-File-with-malicious-Verdict/ta-p/54376" target="_blank"&gt;HERE&lt;/A&gt;&amp;nbsp;should point you in the proper direction&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 16:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/197953#M58796</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-31T16:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to Enable WildFire to block jar file with 'malicious' Verdict</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/198279#M58870</link>
      <description>&lt;P&gt;Dear BPry, many thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked the Anti-Virus profile that is assigned to the applicable rule (Internet to Email Gateway) and the WildFire action is set to "reset-both" for all the listed decoders, including smtp, as can&amp;nbsp;be seen here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Corp Anti-Virus.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13596i3B13266C6E7F570A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Corp Anti-Virus.jpg" alt="Corp Anti-Virus.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would therefore seem that some other setting is at play here that is not immediately obvious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have examined the WildFire&amp;nbsp;Analysis security profile, but this is set to analyze any file type and any application, so there does not appear to be a applicable setting here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WildFire Settings.jpg" style="width: 700px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13600iCDBAF1116FBA4BED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="WildFire Settings.jpg" alt="WildFire Settings.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll continue to investigate..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 17:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/198279#M58870</guid>
      <dc:creator>Steve-Phillips</dc:creator>
      <dc:date>2018-02-01T17:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to Enable WildFire to block jar file with 'malicious' Verdict</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/198518#M58916</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66688"&gt;@Steve-Phillips&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So one thing to potentially think about is if wildfire actually 'knew' about the file yet. A file that hasn't been inspected by WildFire which doesn't have identifyable markers for the Antivirus engine may log an as an 'alert' action until a wildfire signature has been generated for it. That may explain why you are seeing 'alert' actions rather than the desired 'reset-both' with this traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 13:58:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/198518#M58916</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-02T13:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to Enable WildFire to block jar file with 'malicious' Verdict</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/199548#M59124</link>
      <description>&lt;P&gt;Dear BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for your reply and theory for why the email was allowed despite being malicious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have captured the timestamps of the Wildfire evets here, in case that helps accurately diagnose the issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WildFire Summary 1.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13719iD2C9826B64CA4B6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="WildFire Summary 1.jpg" alt="WildFire Summary 1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P class="sectionTitle"&gt;WildFire Analysis Summary&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV class=" x-panel list-view"&gt;&lt;DIV class="x-panel-header x-unselectable"&gt;&lt;SPAN class="x-panel-header-text"&gt;File Information&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="x-panel-bwrap"&gt;&lt;DIV class="x-panel-body"&gt;&lt;DIV class="x-list-wrap"&gt;&lt;DIV class="x-list-body"&gt;&lt;DIV class="x-list-body-inner"&gt;&lt;EM&gt;File Type&lt;/EM&gt; &lt;EM&gt;JAVA JAR&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;File Signer&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;SHA-256&lt;/EM&gt; &lt;EM&gt;149862f4894c9dba2b21b507fa7bde835e6a6a44e35040331c5ab1de3ec4027d&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;SHA1&lt;/EM&gt; &lt;EM&gt;b8aed21b09bda3f02c54c53267ba696a1286e092&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;MD5&lt;/EM&gt; &lt;EM&gt;0ecacad6f88e1ddb859e881c1662b4a9&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;File Size&lt;/EM&gt; &lt;EM&gt;556535 bytes&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;First Seen Timestamp&lt;/EM&gt; &lt;EM&gt;2018-01-26 06:28:06 UTC&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;EM&gt;Verdict&lt;/EM&gt; &lt;EM&gt;&lt;STRONG&gt;malware&lt;/STRONG&gt;&lt;/EM&gt;&lt;DIV class="x-clear"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this information give more visibility to the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 09:37:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enable-wildfire-to-block-jar-file-with-malicious-verdict/m-p/199548#M59124</guid>
      <dc:creator>Steve-Phillips</dc:creator>
      <dc:date>2018-02-08T09:37:04Z</dc:date>
    </item>
  </channel>
</rss>

