<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic JawinaBug Command and Control Traffic Detection(85599) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/jawinabug-command-and-control-traffic-detection-85599/m-p/310586#M80428</link>
    <description>&lt;P&gt;Could you guys please throw some light on "JawinaBug Command and Control Traffic Detection(85599)", there is no information related to could you guys please throw some light on "JawinaBug Command and Control Traffic Detection(85599)", there is no information related to JawinaBug at all&lt;/P&gt;&lt;P&gt;What triggers this signature, what are the IOCs?, Please help&lt;/P&gt;&lt;P&gt;I have seen this signature triggering in internal communication with SQL server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;All I know so far is that the signature is fairly new and by default action of the firewall is reset both connections&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2020 13:19:24 GMT</pubDate>
    <dc:creator>Lalitb</dc:creator>
    <dc:date>2020-02-11T13:19:24Z</dc:date>
    <item>
      <title>JawinaBug Command and Control Traffic Detection(85599)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/jawinabug-command-and-control-traffic-detection-85599/m-p/310586#M80428</link>
      <description>&lt;P&gt;Could you guys please throw some light on "JawinaBug Command and Control Traffic Detection(85599)", there is no information related to could you guys please throw some light on "JawinaBug Command and Control Traffic Detection(85599)", there is no information related to JawinaBug at all&lt;/P&gt;&lt;P&gt;What triggers this signature, what are the IOCs?, Please help&lt;/P&gt;&lt;P&gt;I have seen this signature triggering in internal communication with SQL server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;All I know so far is that the signature is fairly new and by default action of the firewall is reset both connections&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 13:19:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/jawinabug-command-and-control-traffic-detection-85599/m-p/310586#M80428</guid>
      <dc:creator>Lalitb</dc:creator>
      <dc:date>2020-02-11T13:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: JawinaBug Command and Control Traffic Detection(85599)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/jawinabug-command-and-control-traffic-detection-85599/m-p/310613#M80437</link>
      <description>&lt;P&gt;if you enable extended threat pcap, you can see what triggered the signature&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 15:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/jawinabug-command-and-control-traffic-detection-85599/m-p/310613#M80437</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-02-11T15:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: JawinaBug Command and Control Traffic Detection(85599)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/jawinabug-command-and-control-traffic-detection-85599/m-p/310723#M80458</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132869"&gt;@Lalitb&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To add to reaper's comment... you enable the extended_pcap in the vulnerability profile:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="extended_pcap.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23913iCD77C4EA777242A5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="extended_pcap.jpg" alt="extended_pcap.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can edit the length of the extended_pcap as well :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Extended PCAP Length" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23914i79566CF6995F29E3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="extended_length.jpg" alt="Extended PCAP Length" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Extended PCAP Length&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 07:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/jawinabug-command-and-control-traffic-detection-85599/m-p/310723#M80458</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-02-12T07:55:42Z</dc:date>
    </item>
  </channel>
</rss>

