<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA will not update  malware signature from sample malware files (http://wildfire.paloaltonetworks.com/publicapi/test/apk) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422826#M94097</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;It should show up in the firewall logs, but might not show in the portal since its a known test file and they might not log it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jul 2021 22:14:55 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2021-07-28T22:14:55Z</dc:date>
    <item>
      <title>PA will not update  malware signature from sample malware files (http://wildfire.paloaltonetworks.com/publicapi/test/apk)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422697#M94084</link>
      <description>&lt;P&gt;&amp;nbsp;the customer want to test&amp;nbsp; pa wilfire&amp;nbsp; feature .&lt;/P&gt;&lt;P&gt;my test step:&lt;/P&gt;&lt;P&gt;1: from&amp;nbsp;&lt;A title="" href="http://wildfire.paloaltonetworks.com/publicapi/test/apk" target="_blank" rel="noopener"&gt;http://wildfire.paloaltonetworks.com/publicapi/test/apk&lt;/A&gt;, download the sample malware.the traffice throught the pa&lt;/P&gt;&lt;P&gt;2: when we can find the&amp;nbsp; wildire log from firewall&amp;nbsp; and theck the log report ,know the&amp;nbsp; malware files sha256&lt;/P&gt;&lt;P&gt;------------------------------------------------&lt;/P&gt;&lt;P&gt;log: 33, filename: wildfire-test-apk-file.apk&lt;BR /&gt;processed 120151 seconds ago, action: upload success&lt;BR /&gt;vsys_id: 1, session_id: 47055, transaction_id: 5&lt;BR /&gt;file_len: 1434514, flag: 0x801c, file type: apk&lt;BR /&gt;threat id: 52108, user_id: 0, app_id: 109&lt;BR /&gt;from 192.168.5.31/50643 to 34.84.44.247/80&lt;BR /&gt;SHA256: 2751671b591b6969b09f8c032cd89e6ae83a5f3ec819c8b923c673a6286cbec3&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;3:then wait 48 hours,we go to&amp;nbsp; threat db lookup the&amp;nbsp; sha256 value,but we don't find the sha256.&lt;/P&gt;&lt;P&gt;so I think that&amp;nbsp;&amp;nbsp;PA will not update malware signature to antiivirus&amp;nbsp; from sample malware files(&lt;A href="http://wildfire.paloaltonetworks.com/publicapi/test/apk" target="_blank" rel="noopener"&gt;http://wildfire.paloaltonetworks.com/publicapi/test/apk&lt;/A&gt;).is true&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 15:20:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422697#M94084</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2021-07-28T15:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: PA will not update  malware signature from sample malware files (http://wildfire.paloaltonetworks.com/publicapi/test/apk)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422698#M94085</link>
      <description>&lt;P&gt;step 4:&lt;/P&gt;&lt;P&gt;I set up a web server, put the malicious file (apk)on this web server, and then use another host to download the ake malicious file again through HTTP. The traffic passes through the pa firewall. Although the file has been recognized by the firewall's wilfarire function, I also waited 48 hours to update the AV feature library, but the firewall's threat protection does not recognize the malicious file, Therefore, I think PA does not update the signature of the sample to the AV feature library.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 15:32:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422698#M94085</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2021-07-28T15:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: PA will not update  malware signature from sample malware files (http://wildfire.paloaltonetworks.com/publicapi/test/apk)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422826#M94097</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;It should show up in the firewall logs, but might not show in the portal since its a known test file and they might not log it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 22:14:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422826#M94097</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-07-28T22:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: PA will not update  malware signature from sample malware files (http://wildfire.paloaltonetworks.com/publicapi/test/apk)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422875#M94103</link>
      <description>&lt;P&gt;hi&amp;nbsp; Otakarklier:&lt;/P&gt;&lt;P&gt;&amp;nbsp; thanks you reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp; It should show up in the firewall logs, -----which log ,threat log or wildfire log&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; when we do&amp;nbsp; test with step 4, the firewall don't block this malware files (apk) why ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 02:51:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422875#M94103</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2021-07-29T02:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA will not update  malware signature from sample malware files (http://wildfire.paloaltonetworks.com/publicapi/test/apk)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422878#M94104</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="threatvault.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35307i5626CDCBFC52C836/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="threatvault.png" alt="threatvault.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wildfire analysis reprot.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35308i0A244C209BA1F4F8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="wildfire analysis reprot.png" alt="wildfire analysis reprot.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 02:53:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-will-not-update-malware-signature-from-sample-malware-files/m-p/422878#M94104</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2021-07-29T02:53:43Z</dc:date>
    </item>
  </channel>
</rss>

