<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moriagent malware in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/338397#M85098</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got the instruction from the gov. i need to create a custom signature for Mortiagent. They have sent some files.&lt;/P&gt;&lt;P&gt;In the files, there is some IOC's:-&lt;/P&gt;&lt;P&gt;1 - Host base indicator( Which is mentioned some MD5 and SHA values)&lt;/P&gt;&lt;P&gt;2 - Network base indicator( Which is mentioned in some IP address list).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To create a custom signature which &lt;STRONG&gt;pattern and references&lt;/STRONG&gt; i need to choose ? below is the snort rule:-&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:" MoriAgent Beacon HTTP Request"; content:"/Index.php?i="; depth:200; content:"&amp;amp;t="; within:64; content:"HTTP/1.1"; within:64; content:"Content-Type: application/json"; within:32; content:"Content-Length: 0"; within:90; threshold:type limit,track by_src,count&lt;/P&gt;&lt;P&gt;1,seconds 120; sid:1000001; rev:001;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- For the IP address, i need to create an EDL to block all the IP's?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jul 2020 10:59:32 GMT</pubDate>
    <dc:creator>Jafar_Hussain</dc:creator>
    <dc:date>2020-07-14T10:59:32Z</dc:date>
    <item>
      <title>Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337219#M84936</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have much idea about Moriagent malware, i got an instruction i need to create a rule or block this malware&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;How to stop MortiAgent Malware using snort rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to stop the MoriAgent malware by applying /using snort rule.&lt;/P&gt;&lt;P&gt;How to configure this in Palo alto ?&lt;/P&gt;&lt;P&gt;Below are snort rule.&lt;/P&gt;&lt;P&gt;1. The below SNORT rule can be used to detect the MoriAgent Beacon.&lt;BR /&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:" MoriAgent Beacon&lt;BR /&gt;HTTP Request"; content:"/Index.php?i="; depth:200; content:"&amp;amp;t="; within:64;&lt;BR /&gt;content:"HTTP/1.1"; within:64; content:"Content-Type: application/json"; within:32;&lt;BR /&gt;content:"Content-Length: 0"; within:90; threshold:type limit,track by_src,count&lt;BR /&gt;1,seconds 120; sid:1000001; rev:001;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help me to understand what I need to do, I searched about this but didn't get much information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 17:53:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337219#M84936</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-08T17:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337257#M84941</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Check the Threat Vault at the link below for Morti and there's already two antivirus signatures for MortiAgent and a WildFire signature. If you don't find that suitable defense you'll need to look into creating your own custom threat signature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/custom-signatures.html" target="_self"&gt;&lt;STRONG&gt;Custom Threat Signature&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com" target="_self"&gt;&lt;STRONG&gt;Threat Vault&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 19:42:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337257#M84941</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-08T19:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337278#M84948</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the information.&lt;/P&gt;&lt;P class=""&gt;I was unable to find&lt;SPAN&gt; MortiAgent in the PAN threat vault&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;It is mandatory to create a custom signature for Mortiagent malware.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;I have gone through the documents which you provided. if i will create a customer signature what is the threat id we need to use.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 20:40:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337278#M84948</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-08T20:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337337#M84952</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The threat ID you select doesn't matter, as long as it's within the available range. Some people make enough to actually create a format for numbering their custom IDs, others don't follow one and simply increment with each entry.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 04:19:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337337#M84952</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-09T04:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337348#M84955</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the information, i will check this.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 05:12:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337348#M84955</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-09T05:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337548#M84977</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Make sure your PAN objects are setup for AntiVirus, AntiSpyware, URL Filtering, WildFire, and DNS Sink hole. Then make sure they are applied to all inbound/outbound policies so the traffic is inspected. Also make sure your PAN has the latest Dynamic signatures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having the PAN setup for this is a great way to dynamically block malicious traffic. Along with your other products, i.e. desktop antivirus, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 19:46:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337548#M84977</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-07-09T19:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337661#M84985</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply. i have found two signature of mortiagent malware below is the snap:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1594364268446.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26716i496DCD7A21703B69/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1594364268446.png" alt="Jafar_Hussain_0-1594364268446.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Apart from this. it is a mandatory to create a custom signature?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 06:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337661#M84985</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-10T06:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337757#M85006</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If you have all the other security features turned on and dynamic updates working and up to date. I would say you are good, however check the endpoint AV and make sure its working and maybe even run a full scan.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 15:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337757#M85006</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-07-10T15:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337775#M85012</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the valuable information.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 17:29:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/337775#M85012</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-10T17:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/338397#M85098</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got the instruction from the gov. i need to create a custom signature for Mortiagent. They have sent some files.&lt;/P&gt;&lt;P&gt;In the files, there is some IOC's:-&lt;/P&gt;&lt;P&gt;1 - Host base indicator( Which is mentioned some MD5 and SHA values)&lt;/P&gt;&lt;P&gt;2 - Network base indicator( Which is mentioned in some IP address list).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To create a custom signature which &lt;STRONG&gt;pattern and references&lt;/STRONG&gt; i need to choose ? below is the snort rule:-&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:" MoriAgent Beacon HTTP Request"; content:"/Index.php?i="; depth:200; content:"&amp;amp;t="; within:64; content:"HTTP/1.1"; within:64; content:"Content-Type: application/json"; within:32; content:"Content-Length: 0"; within:90; threshold:type limit,track by_src,count&lt;/P&gt;&lt;P&gt;1,seconds 120; sid:1000001; rev:001;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- For the IP address, i need to create an EDL to block all the IP's?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 10:59:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/338397#M85098</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-14T10:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/338689#M85137</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If its a 'White' IOC notice, I wouldnt worry about it but I guess a EDL or a special policy with a block for those IP's would do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 15:14:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/338689#M85137</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-07-15T15:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Moriagent malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/338720#M85141</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks. i have found the pattern of the signature.&lt;/P&gt;&lt;DIV&gt;(&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;I&lt;/SPAN&gt;&lt;SPAN&gt;n&lt;/SPAN&gt;&lt;SPAN&gt;d&lt;/SPAN&gt;&lt;SPAN&gt;e&lt;/SPAN&gt;x&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;p&lt;/SPAN&gt;hp&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN&gt;i&lt;/SPAN&gt;= and &lt;SPAN&gt;&amp;amp;&lt;/SPAN&gt;t and HT&lt;SPAN&gt;T&lt;/SPAN&gt;P/1&lt;SPAN&gt;.&lt;/SPAN&gt;1 and Cont&lt;SPAN&gt;e&lt;/SPAN&gt;&lt;SPAN&gt;n&lt;/SPAN&gt;&lt;SPAN&gt;t&lt;/SPAN&gt;&lt;SPAN&gt;-Type&lt;/SPAN&gt;: a&lt;SPAN&gt;pp&lt;/SPAN&gt;l&lt;SPAN&gt;i&lt;/SPAN&gt;c&lt;SPAN&gt;a&lt;/SPAN&gt;ti&lt;SPAN&gt;o&lt;/SPAN&gt;n/&lt;SPAN&gt;js&lt;/SPAN&gt;on)&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In the custom signature which condition i need to follow "And" condition "OR" condition. and for the qualifier which information i need to add.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 15 Jul 2020 17:31:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moriagent-malware/m-p/338720#M85141</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-07-15T17:31:40Z</dc:date>
    </item>
  </channel>
</rss>

