Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

malware.azjf C2 traffic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

malware.azjf C2 traffic

L2 Linker

Hi,

I am seeing a lot of traffic being identified as malware.azjf C2 traffic over the last couple of days since the last threat update. I have noticed a pattern that users are visiting Wordpress websites that use the owl carousel plugin and checking these sites on VT they come up clean so appears to be a false positive.

Is anyone else aware of this going on?

5 REPLIES 5

L0 Member

Hi,

I have came across one from 17 November 2021. Same here, it points to a WordPress site with a carousel plugin.

Here are the IOCs:

IP: 194.72.147.94 on port 443

urls:

  • brunepark[.]gfmat[.]org
  • brunepark[.]gfmat[.]org/wp-content/plugins/js_composer/assets/lib/owl-carousel2-dist/owl.carousel.min.js?ver=6.0.5
  • brunepark[.]gfmat[.]org/wp-content/themes/ed-school/assets/fonts/ed-icon.ttf?nj4a9z

 

L0 Member

Same here. I have hits for at least the following sites,(likely more though), however the commonality seems to be the carousel plugin.

As far as I can tell, this is not malicious traffic, rather a false positive match for C2 traffic.

URLs:
- www[.]toshibaaudio[.]com/wp-content/themes/porto/js/libs/owl.carousel.min.js?ver=2.3.4
- www[.]thepartnership[.]org/wp-content/plugins/gyan-elements/assets/js/owl.carousel.min.js?ver=2.3.4
- uvc[.]org/wp-content/themes/startit/assets/js/modules/plugins/owl.carousel.min.js?ver=5.8.2
- www[.]integralpartnersllc[.]com/wp-content/themes/integral-partners/js/owl_slider/owl.carousel.min.js?ver=1637146460

L5 Sessionator

Palo Alto Networks confirmed that it was a False Positive. The signature "malware.azjf C2 traffic(446823108)" will be disabled in Anti-Virus version 3905.

Hi ! can u let us know, where did you get this? the official quote pelase

I'm a Palo Alto Networks employee, so I can check the signature status. (I just updated my profile with a job title.)

  • 3975 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!