<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocking action with Virus Threat, but can't find information in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8192#M6055</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a user trying to access a website webinar and they are getting blocked with AV threat name Trojan/Js.Iframe.bgw ID: 259252.&amp;nbsp; The details are as follows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="list"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Log&lt;/TD&gt;&lt;TD class="dashboard"&gt;THREAT&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Type&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;virus&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Receive Time&lt;/TD&gt;&lt;TD class="dashboard"&gt;2010/03/22 14:03:23&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Generation Time&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;2010/03/22 14:03:17&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Threat Name&lt;/TD&gt;&lt;TD class="dashboard"&gt;Trojan/Js.Iframe.bgw&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Threat ID&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;259252&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Direction&lt;/TD&gt;&lt;TD class="dashboard"&gt;server-to-client&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;From Zone&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;FW_UplinkOutsid&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;To Zone&lt;/TD&gt;&lt;TD class="dashboard"&gt;FW_UplinkInside&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Attacker&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;4.53.17.200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Victim&lt;/TD&gt;&lt;TD class="dashboard"&gt;10.0.99.20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;From User&lt;/TD&gt;&lt;TD class="dashboard"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;To User&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;From Port&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;80&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;To Port&lt;/TD&gt;&lt;TD class="dashboard"&gt;3376&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Protocol&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;tcp&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Application&lt;/TD&gt;&lt;TD class="dashboard"&gt;web-browsing&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Action&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;deny&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Severity&lt;/TD&gt;&lt;TD class="dashboard"&gt;medium&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Rule&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;Internet&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Ingress I/F&lt;/TD&gt;&lt;TD class="dashboard"&gt;ethernet1/5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Egress I/F&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;ethernet1/6&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Log Action&lt;/TD&gt;&lt;TD class="dashboard"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Virtual System&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;vsys3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Session Id&lt;/TD&gt;&lt;TD class="dashboard"&gt;461655&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Count&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Configuration Version&lt;/TD&gt;&lt;TD class="dashboard"&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Category&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;any&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Others&lt;/TD&gt;&lt;TD class="dashboard"&gt;hpbroadband.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;SSL Decrypted&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;NAT Applied&lt;/TD&gt;&lt;TD class="dashboard"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Packet Capture&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Captive Portal&lt;/TD&gt;&lt;TD class="dashboard"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Proxy Transaction&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Serial #&lt;/TD&gt;&lt;TD class="dashboard"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Mar 2010 14:33:11 GMT</pubDate>
    <dc:creator>aveva_palo</dc:creator>
    <dc:date>2010-03-22T14:33:11Z</dc:date>
    <item>
      <title>Blocking action with Virus Threat, but can't find information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8192#M6055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a user trying to access a website webinar and they are getting blocked with AV threat name Trojan/Js.Iframe.bgw ID: 259252.&amp;nbsp; The details are as follows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="list"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Log&lt;/TD&gt;&lt;TD class="dashboard"&gt;THREAT&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Type&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;virus&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Receive Time&lt;/TD&gt;&lt;TD class="dashboard"&gt;2010/03/22 14:03:23&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Generation Time&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;2010/03/22 14:03:17&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Threat Name&lt;/TD&gt;&lt;TD class="dashboard"&gt;Trojan/Js.Iframe.bgw&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Threat ID&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;259252&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Direction&lt;/TD&gt;&lt;TD class="dashboard"&gt;server-to-client&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;From Zone&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;FW_UplinkOutsid&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;To Zone&lt;/TD&gt;&lt;TD class="dashboard"&gt;FW_UplinkInside&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Attacker&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;4.53.17.200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Victim&lt;/TD&gt;&lt;TD class="dashboard"&gt;10.0.99.20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;From User&lt;/TD&gt;&lt;TD class="dashboard"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;To User&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;From Port&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;80&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;To Port&lt;/TD&gt;&lt;TD class="dashboard"&gt;3376&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Protocol&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;tcp&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Application&lt;/TD&gt;&lt;TD class="dashboard"&gt;web-browsing&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Action&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;deny&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Severity&lt;/TD&gt;&lt;TD class="dashboard"&gt;medium&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Rule&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;Internet&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Ingress I/F&lt;/TD&gt;&lt;TD class="dashboard"&gt;ethernet1/5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Egress I/F&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;ethernet1/6&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Log Action&lt;/TD&gt;&lt;TD class="dashboard"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Virtual System&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;vsys3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Session Id&lt;/TD&gt;&lt;TD class="dashboard"&gt;461655&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Count&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Configuration Version&lt;/TD&gt;&lt;TD class="dashboard"&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Category&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;any&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Others&lt;/TD&gt;&lt;TD class="dashboard"&gt;hpbroadband.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;SSL Decrypted&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;NAT Applied&lt;/TD&gt;&lt;TD class="dashboard"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Packet Capture&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Captive Portal&lt;/TD&gt;&lt;TD class="dashboard"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left_alternate"&gt;Proxy Transaction&lt;/TD&gt;&lt;TD class="dashboard_alternate"&gt;no&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left" class="dashboard_left"&gt;Serial #&lt;/TD&gt;&lt;TD class="dashboard"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Mar 2010 14:33:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8192#M6055</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2010-03-22T14:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking action with Virus Threat, but can't find information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8193#M6056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you think this is a false positive you can set an exception for this by simply clicking on the threat name from the threat log, then click on "show" next to exceptions, the click on "add".&lt;/P&gt;&lt;P&gt;To pursue this further you will need to call into support so we can take look at this and perhaps refer this to engineering to correct our content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Mar 2010 19:37:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8193#M6056</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-03-23T19:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking action with Virus Threat, but can't find information</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8194#M6057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this issue went after an AV and threat definition update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Mar 2010 11:21:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-action-with-virus-threat-but-can-t-find-information/m-p/8194#M6057</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2010-03-26T11:21:17Z</dc:date>
    </item>
  </channel>
</rss>

