<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Detecting a lot of spyware, 13190 (Smoke.Loader Command And Control Traffic) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-a-lot-of-spyware-13190-smoke-loader-command-and/m-p/10439#M7695</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This might be a case of false positive. Please open a Support case with the tech support and pcaps as suggested in the document so that we can further look into this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2769"&gt;https://live.paloaltonetworks.com/docs/DOC-2769&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jul 2012 17:47:15 GMT</pubDate>
    <dc:creator>zarina</dc:creator>
    <dc:date>2012-07-18T17:47:15Z</dc:date>
    <item>
      <title>Detecting a lot of spyware, 13190 (Smoke.Loader Command And Control Traffic)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-a-lot-of-spyware-13190-smoke-loader-command-and/m-p/10438#M7694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a user that's triggering this alert frequently when doing normal Internet browsing.&amp;nbsp; Some detections are to bbc.com and other news outlet sites..&amp;nbsp; Nothing obvious comes up when analyzing the computer, so I was wondering if I could find out exactly what this signature is looking for.&amp;nbsp; I already checked the Threat Vault and it only provided the same information my PA device did.&amp;nbsp; Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 23:20:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-a-lot-of-spyware-13190-smoke-loader-command-and/m-p/10438#M7694</guid>
      <dc:creator>mfcuns</dc:creator>
      <dc:date>2012-07-17T23:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting a lot of spyware, 13190 (Smoke.Loader Command And Control Traffic)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-a-lot-of-spyware-13190-smoke-loader-command-and/m-p/10439#M7695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This might be a case of false positive. Please open a Support case with the tech support and pcaps as suggested in the document so that we can further look into this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2769"&gt;https://live.paloaltonetworks.com/docs/DOC-2769&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 17:47:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-a-lot-of-spyware-13190-smoke-loader-command-and/m-p/10439#M7695</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-07-18T17:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting a lot of spyware, 13190 (Smoke.Loader Command And Control Traffic)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-a-lot-of-spyware-13190-smoke-loader-command-and/m-p/10440#M7696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What was the result of the Smoke.Loader spyware.&amp;nbsp; We also saw a significant number of matches to this signature around July 5th/6th and nothing since then. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 18:12:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-a-lot-of-spyware-13190-smoke-loader-command-and/m-p/10440#M7696</guid>
      <dc:creator>robertb</dc:creator>
      <dc:date>2012-07-31T18:12:29Z</dc:date>
    </item>
  </channel>
</rss>

