<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Verification of malware events in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90677#M18134</link>
    <description>&lt;P&gt;I know the destination and I have doubts about validity of it is being a part of the C&amp;amp;C.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jul 2020 13:39:25 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2020-07-06T13:39:25Z</dc:date>
    <item>
      <title>Verification of malware events</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90585#M18121</link>
      <description>&lt;P&gt;I am seeing :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Maze_DNS_CnC.png" style="width: 924px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7115i079440B1DE92D37B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Maze_DNS_CnC.png" alt="Maze_DNS_CnC.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but am having trouble verifying the validity of these events.&lt;/P&gt;
&lt;P&gt;No RBLs, including IBM X-Force exchange list the resolved IP as a C&amp;amp;C.&lt;/P&gt;
&lt;P&gt;Is there a way to determine how CP decided that this host belongs to the Maze C&amp;amp;C?&lt;/P&gt;
&lt;P&gt;My Watchtower app is getting hammered with alarms, but the two internal hosts that are being flagged are unlikely to really be compromised.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 15:44:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90585#M18121</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2020-07-05T15:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Verification of malware events</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90613#M18129</link>
      <description>Send me the unobscured stuff out-of-band, I can ask around.</description>
      <pubDate>Sun, 05 Jul 2020 23:27:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90613#M18129</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-05T23:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Verification of malware events</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90638#M18133</link>
      <description>&lt;P&gt;It is right there in the logs. There is a DNS request for C&amp;amp;C IP address.&lt;/P&gt;
&lt;P&gt;These hosts you are talking about, are they your internal DNS servers? If they are, the infection can be somewhere else. Start DNS logging on those servers to see which machines request DNS entries for C&amp;amp;C&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 08:47:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90638#M18133</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-07-06T08:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: Verification of malware events</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90677#M18134</link>
      <description>&lt;P&gt;I know the destination and I have doubts about validity of it is being a part of the C&amp;amp;C.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 13:39:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90677#M18134</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2020-07-06T13:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Verification of malware events</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90681#M18135</link>
      <description>&lt;P&gt;Just dropped you an email.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 13:56:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90681#M18135</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2020-07-06T13:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Verification of malware events</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90705#M18139</link>
      <description>&lt;P&gt;In this case, raise this with TAC.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 17:27:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90705#M18139</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-07-06T17:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: Verification of malware events</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90709#M18140</link>
      <description>&lt;P&gt;So this ended-up a false-positive by IRT and was that way for around 24 hours.&lt;/P&gt;
&lt;P&gt;Is there any way to address these issues in real-time?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 18:26:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90709#M18140</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2020-07-06T18:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Verification of malware events</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90735#M18141</link>
      <description>Even after we revert a given IOC, caching means it can take a few hours for the issue to resolve.&lt;BR /&gt;Local changes to the Threat Prevention policy can be made in the meantime and take effect when you push policy.</description>
      <pubDate>Tue, 07 Jul 2020 01:03:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Verification-of-malware-events/m-p/90735#M18141</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-07T01:03:13Z</dc:date>
    </item>
  </channel>
</rss>

