cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Suspicious TLS Evasion Found

L0 Member

PA-3020

 

Recently I've had several users get a "Virus/Spyware Download Blocked" page on random sites.  Normally they get it on google searches.  If they refresh, sometimes the error stays, and sometimes it just takes them to the page.  

 

It even happened to me the first time I tried coming to this site, but a refresh took me here.  Here's an example of the error for another site I tried to go to.

 

virusSpywareDownloadBlocked.png

 

When I log into the PA, and look under Monitor->Threat, I have the following errors:

 

Monitor_Spyware.png

 

 

I'm fairly new to PA systems, and it seemed odd to me, that my IP address was listed as the Attacker, and google was listed as the Victim.  Also, for my traffic at least, they are listed as Suspicious TLS Evasion Found, on what looks to be google ads.  I listed the URL's at the top right of the above image.  Any ideas on what could be causing this.  

 

In addition, we've also seen things like broken images from sites, that show as the same error in the PA "Suspicious TLS Evasion Found", or Suspicious HTTP Evasion Found.

Who Me Too'd this topic