- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-14-2026 12:33 PM
I have noticed that PA NGFW sees this threat trojan/Win32.deceiver.d using Logon.exe from PCs in a specific zone (zone 1) going to our DCs that happen to be in a different zone (zone 2). I have had a couple of users say they have to type in their credentials a couple of times but we blamed DUO for that. In the Threat log I see only a few of the PCs in zone 1 application: ms-ds-smbv3, Type: virus or wildfire-virus, using port 445. When I look in the Wildfire Submissions: File name: logon.exe action: block.
We have Malwarebytes and Cortex - when I scan those machines - they come back clean.
Anyone else having this issue?
09-17-2026 11:11 PM
Maybe the logon.exe is dynamic and each time is different and Wildfire need to scan it. You can create rule that matches the app, the url and attach wildfire profile with not a "Hold" mode and also check the logs that it is not the Inline ML Wildfire that uses prebuild AI models for scanning without checking the Wildfire cloud.
See: "The system applies the fall back policy rule configured by the administrator, which determines whether to enable (permissive) or block (protective) the file."
File Handling and Analysis in Advanced WildFire
Hold Mode for WildFire Real-Time Signature Lookup
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

