<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zero Access question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8242#M6088</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;End user has no access to signatures. "ZeroAccess" is a category where Trojan Horse hides itself. PANW can verify each exe if proper policies are applied. And can detect Trojan hourse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Provide me more specific detail query on "ZeroAccess Alert".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Mar 2015 20:22:20 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2015-03-19T20:22:20Z</dc:date>
    <item>
      <title>Zero Access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8240#M6086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am new to this website, so I apologize if this is in the wrong location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone clarify for me what the ZeroAccess alert in the Palo Alto is triggering upon? How do I review the signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for you assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Mar 2015 19:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8240#M6086</guid>
      <dc:creator>Fred_Zierold</dc:creator>
      <dc:date>2015-03-19T19:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8241#M6087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depending on which ID it is giving you, you can look in the threat vault for a description:&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, here is a listing for the first ID (13298):&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13298" title="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13298"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13298&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Mar 2015 20:06:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8241#M6087</guid>
      <dc:creator>Dz3015</dc:creator>
      <dc:date>2015-03-19T20:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8242#M6088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;End user has no access to signatures. "ZeroAccess" is a category where Trojan Horse hides itself. PANW can verify each exe if proper policies are applied. And can detect Trojan hourse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Provide me more specific detail query on "ZeroAccess Alert".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Mar 2015 20:22:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8242#M6088</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2015-03-19T20:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8243#M6089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the alert we are seeing.&amp;nbsp;&amp;nbsp; I just want a better idea what it is triggering on.&amp;nbsp; We had another system which gave us many many false positive ZeroAccess alerts.&amp;nbsp; Before I start pulling computers for malware analysis, I want to find out what is causing this to trigger.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="retro"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="retro" width="180"&gt;Name:&lt;/TD&gt;&lt;TD class="retro-value"&gt;ZeroAccess.Gen Command and Control Traffic&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="retro" width="180"&gt;ID:&lt;/TD&gt;&lt;TD class="retro-value"&gt;13235&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="retro"&gt;Description:&lt;/TD&gt;&lt;TD class="retro-value"&gt;&amp;nbsp; This signature detects ZeroAccess.Gen Command and Control Traffic.&amp;nbsp; &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2015 17:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8243#M6089</guid>
      <dc:creator>Fred_Zierold</dc:creator>
      <dc:date>2015-03-23T17:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8244#M6090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System is under botnet attach, please refer following link.&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13235" title="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13235"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13235&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know for additional query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2015 17:13:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8244#M6090</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2015-03-23T17:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8245#M6091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;13235 is a generic botnet detector. It is typically triggered with requests to known Command &amp;amp; Control (C&amp;amp;C) servers, hostnames, or IPs.&amp;nbsp; Please find more information.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13235" rel="nofollow" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #006595;"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13235&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A full AV scan of the affected machine would likely show results, as long as any associated malware has not disabled the AV scanner. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2015 17:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8245#M6091</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2015-03-23T17:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8246#M6092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is a false positive.&amp;nbsp; I just spoke with the person whose computer this is and it was reimaged for zeroaccess over a month ago.&amp;nbsp; Yet the alerts are continuing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I spoke with the original analyst on the case and he feels this alert is generating alerts on inbound traffic.&amp;nbsp; The Palo Alto screen shows that our computer is attacking, however upon packet review the inbound traffic is causing the alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hshah do you work for PA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2015 17:59:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8246#M6092</guid>
      <dc:creator>Fred_Zierold</dc:creator>
      <dc:date>2015-03-23T17:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8247#M6093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Threat log direction should be "server-to-client", if yes. Than it means attacker is on internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you think its a false positive, than you might want to create exception for that. Let me know if you need any help with that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2015 18:12:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8247#M6093</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2015-03-23T18:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8248#M6094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fred, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sounds right.&amp;nbsp; Perhaps the system is still on client lists for the C&amp;amp;C servers so they are still attempting to communicate.&amp;nbsp; Does that system have it's own public IP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2015 19:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-access-question/m-p/8248#M6094</guid>
      <dc:creator>Dz3015</dc:creator>
      <dc:date>2015-03-23T19:06:54Z</dc:date>
    </item>
  </channel>
</rss>

