- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-18-2021 05:13 AM
Hi,
I am seeing a lot of traffic being identified as malware.azjf C2 traffic over the last couple of days since the last threat update. I have noticed a pattern that users are visiting Wordpress websites that use the owl carousel plugin and checking these sites on VT they come up clean so appears to be a false positive.
Is anyone else aware of this going on?
11-18-2021 08:04 AM - edited 11-18-2021 08:05 AM
Hi,
I have came across one from 17 November 2021. Same here, it points to a WordPress site with a carousel plugin.
Here are the IOCs:
IP: 194.72.147.94 on port 443
urls:
11-18-2021 08:18 AM - edited 11-18-2021 08:21 AM
Same here. I have hits for at least the following sites,(likely more though), however the commonality seems to be the carousel plugin.
As far as I can tell, this is not malicious traffic, rather a false positive match for C2 traffic.
URLs:
- www[.]toshibaaudio[.]com/wp-content/themes/porto/js/libs/owl.carousel.min.js?ver=2.3.4
- www[.]thepartnership[.]org/wp-content/plugins/gyan-elements/assets/js/owl.carousel.min.js?ver=2.3.4
- uvc[.]org/wp-content/themes/startit/assets/js/modules/plugins/owl.carousel.min.js?ver=5.8.2
- www[.]integralpartnersllc[.]com/wp-content/themes/integral-partners/js/owl_slider/owl.carousel.min.js?ver=1637146460
11-18-2021 05:32 PM
Palo Alto Networks confirmed that it was a False Positive. The signature "malware.azjf C2 traffic(446823108)" will be disabled in Anti-Virus version 3905.
11-18-2021 11:57 PM
Hi ! can u let us know, where did you get this? the official quote pelase
11-19-2021 01:26 AM
I'm a Palo Alto Networks employee, so I can check the signature status. (I just updated my profile with a job title.)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!