<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A Network Trojan was Detected! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974078#M1019062</link>
    <description>&lt;P&gt;My FirePower Detects&amp;nbsp;&lt;SPAN&gt;A Network Trojan on my Controller domain (A Network Trojan was Detected).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Event:&amp;nbsp;INDICATOR-COMPROMISE Suspicious .pw dns query (1:28039:5) I have destination Ip addres (&lt;A data-type="ip" href="https://150.31.44.222/events/index.cgi#" onclick="cdi( &amp;quot;Events_orig_starttime&amp;quot;, &amp;quot;1474271863&amp;quot; ); cdi( &amp;quot;Events_orig_endtime&amp;quot;, &amp;quot;1474275463&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;app_proto_category&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;http_hostname&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;smtp_to&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;client_category&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;http_uri&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;web_app_category&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;web_app_tag&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;app_proto_tag&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;smtp_attachments&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;xff&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;dst_user_id&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;mpls_label&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;client_tag&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;smtp_from&amp;quot; ); cdi( &amp;quot;page&amp;quot;, &amp;quot;1&amp;quot; ); cdi( &amp;quot;checked&amp;quot;, &amp;quot;priority=1!,!app_proto_id=0!,!time=1474271348:715868!,!sensor=1!,!dport=53:17:0!,!fw_policy=D5DE71347BF611E69732F6B4FED06007!,!sig_gen=1!,!na_policy=C7D64570530C11E6B8059B827B657FA4!,!dst_country=643:00000000000000000000FFFFC2558150:1474271348!,!ssl_status=1|0|0|0000000000000000000000000000000000000000!,!security_zone_egress=24BF2B1E42B711E68C95DB9D03FD1F96!,!ips_policy=30EE6F5075D211E69E40ECC477D0C6D0!,!inline_result=0!,!src_user_id=0!,!web_app=0!,!interface_ingress=2FBB949442B711E6AF17EC8A2290392D!,!smart_risk=0!,!src=00000000000000000000FFFF961F2CCF!,!interface_egress=2480496C42B711E68C95DB9D03FD1F96!,!ioc_count=0!,!security_zone_ingress=2FFAB41242B711E6AF17EC8A2290392D!,!smart_productivity=0!,!event=1:28039:5!,!fw_rule_name=!,!vlan_id=2!,!client=0!,!classification=35!,!sport=61355:17!,!src_country=392:00000000000000000000FFFF961F2CCF:1474271348!,!dst=00000000000000000000FFFFC2558150!,!impact=3&amp;quot; ); cdi( &amp;quot;dst&amp;quot;, &amp;quot;00000000000000000000FFFFC2558150&amp;quot; ); setFormForNewWindow(); cdi_submit( &amp;quot;/events/index.cgi&amp;quot; ); _setTarget = false; return false;" target="_blank"&gt;194.85.129.80&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I already have read about this intrusion event. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And I use&amp;nbsp;brightcloud.com for chesk this destination address. (No Threats Found) I checkd my controller for viruses. And did not found it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is it mean that I have&amp;nbsp;a false positive? Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:08:16 GMT</pubDate>
    <dc:creator>n.avramenko87</dc:creator>
    <dc:date>2019-03-12T13:08:16Z</dc:date>
    <item>
      <title>A Network Trojan was Detected!</title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974078#M1019062</link>
      <description>&lt;P&gt;My FirePower Detects&amp;nbsp;&lt;SPAN&gt;A Network Trojan on my Controller domain (A Network Trojan was Detected).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Event:&amp;nbsp;INDICATOR-COMPROMISE Suspicious .pw dns query (1:28039:5) I have destination Ip addres (&lt;A data-type="ip" href="https://150.31.44.222/events/index.cgi#" onclick="cdi( &amp;quot;Events_orig_starttime&amp;quot;, &amp;quot;1474271863&amp;quot; ); cdi( &amp;quot;Events_orig_endtime&amp;quot;, &amp;quot;1474275463&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;app_proto_category&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;http_hostname&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;smtp_to&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;client_category&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;http_uri&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;web_app_category&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;web_app_tag&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;app_proto_tag&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;smtp_attachments&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;xff&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;dst_user_id&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;mpls_label&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;client_tag&amp;quot; ); cdi( &amp;quot;remove_columns&amp;quot;, &amp;quot;smtp_from&amp;quot; ); cdi( &amp;quot;page&amp;quot;, &amp;quot;1&amp;quot; ); cdi( &amp;quot;checked&amp;quot;, &amp;quot;priority=1!,!app_proto_id=0!,!time=1474271348:715868!,!sensor=1!,!dport=53:17:0!,!fw_policy=D5DE71347BF611E69732F6B4FED06007!,!sig_gen=1!,!na_policy=C7D64570530C11E6B8059B827B657FA4!,!dst_country=643:00000000000000000000FFFFC2558150:1474271348!,!ssl_status=1|0|0|0000000000000000000000000000000000000000!,!security_zone_egress=24BF2B1E42B711E68C95DB9D03FD1F96!,!ips_policy=30EE6F5075D211E69E40ECC477D0C6D0!,!inline_result=0!,!src_user_id=0!,!web_app=0!,!interface_ingress=2FBB949442B711E6AF17EC8A2290392D!,!smart_risk=0!,!src=00000000000000000000FFFF961F2CCF!,!interface_egress=2480496C42B711E68C95DB9D03FD1F96!,!ioc_count=0!,!security_zone_ingress=2FFAB41242B711E6AF17EC8A2290392D!,!smart_productivity=0!,!event=1:28039:5!,!fw_rule_name=!,!vlan_id=2!,!client=0!,!classification=35!,!sport=61355:17!,!src_country=392:00000000000000000000FFFF961F2CCF:1474271348!,!dst=00000000000000000000FFFFC2558150!,!impact=3&amp;quot; ); cdi( &amp;quot;dst&amp;quot;, &amp;quot;00000000000000000000FFFFC2558150&amp;quot; ); setFormForNewWindow(); cdi_submit( &amp;quot;/events/index.cgi&amp;quot; ); _setTarget = false; return false;" target="_blank"&gt;194.85.129.80&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I already have read about this intrusion event. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And I use&amp;nbsp;brightcloud.com for chesk this destination address. (No Threats Found) I checkd my controller for viruses. And did not found it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is it mean that I have&amp;nbsp;a false positive? Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974078#M1019062</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2019-03-12T13:08:16Z</dc:date>
    </item>
    <item>
      <title>To be safe I'd go to the</title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974079#M1019064</link>
      <description>&lt;P&gt;To be safe I'd go to the machine on your network that is the source address and run malwarebytes or spybot just to make sure. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 14:05:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974079#M1019064</guid>
      <dc:creator>bhartsfield</dc:creator>
      <dc:date>2016-09-20T14:05:20Z</dc:date>
    </item>
    <item>
      <title>Hello! Thank for your advice</title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974080#M1019065</link>
      <description>&lt;P&gt;Hello! Thank for your advice.Checked by spybot. All good.&lt;BR /&gt;But I want to no how it works.&lt;BR /&gt;And what I have. I have intrusion events for this server.&lt;BR /&gt;And I have Intrusion policy with DROP WHEN INLINE.&lt;BR /&gt;But I see than these event did not block.(inline result in intrusion events)&lt;BR /&gt;Is it ok? O my intrusion policy configured wrong?&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 08:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974080#M1019065</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-09-22T08:22:19Z</dc:date>
    </item>
    <item>
      <title>Hello Avramenko87,</title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974081#M1019066</link>
      <description>&lt;P&gt;Hello Avramenko87,&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;policy looks fine. If the policy is set like Drop when inline , then the events should be blocked. To check further on this we may need the packet capture and match the contents for this specific SID. Another suggestion I have is you can keep the default policy as balanced security and connectivity and that is better for performance.&lt;/P&gt;
&lt;P&gt;Refer the link for better understanding of Intrusion rules.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Intrusion-Rule-Writing.html&lt;/P&gt;
&lt;P&gt;Rate and mark correct if the post helps you&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 08:38:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974081#M1019066</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-09-22T08:38:03Z</dc:date>
    </item>
    <item>
      <title>Thank you! I will try and</title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974082#M1019067</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Thank you! I will try and tell what I got!&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 08:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974082#M1019067</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-09-22T08:48:39Z</dc:date>
    </item>
    <item>
      <title>I did not solve a problem. I</title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974083#M1019068</link>
      <description>&lt;P&gt;I did not solve a problem. I tryed to change intrusion policy, &lt;SPAN&gt;Default Network Analysis Policy,&lt;/SPAN&gt;default action.&amp;nbsp;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you explaim to me what you mean:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To check further on this we may need the packet capture and match the contents for this specific SID.How can I do this?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I want to solve my problem. Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 13:57:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974083#M1019068</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-09-22T13:57:46Z</dc:date>
    </item>
    <item>
      <title>Two things</title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974084#M1019069</link>
      <description>&lt;P&gt;Two things&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1) Just becasue you have drop when inline checked doesnt mean everything will be droped. &amp;nbsp;Each individual signature can be set to log only or log and drop so it is possible that they rule is set just to log but not block. &amp;nbsp;You would need to look at that specific rule inside your policy to see how it is configured.&lt;/P&gt;
&lt;P&gt;2) Since it said possible trojan, do you also have AMP setup on this server? &amp;nbsp;If so, did you look to see if AMP picked up anything on the trojan?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 14:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974084#M1019069</guid>
      <dc:creator>bhartsfield</dc:creator>
      <dc:date>2016-09-22T14:05:32Z</dc:date>
    </item>
    <item>
      <title>Friends! May be somebody can</title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974085#M1019070</link>
      <description>&lt;P&gt;&lt;EM&gt;Friends! May be somebody can show for me your acces control policy.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;I suspect that configured my policy wrong.Thank you!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;P.S. And what about access control policy. Can I use several &amp;nbsp;access policys like on the picture? Or it used only when a have several fire power sensors?&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2016 07:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974085#M1019070</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-09-23T07:24:17Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974086#M1019071</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I wouldn't recommend to focus on the single finding. &amp;nbsp;I&lt;SPAN&gt;ndicator-of-compromise category contains rules that should be&amp;nbsp;&lt;/SPAN&gt;used for the detection of a positively compromised system and&lt;SPAN&gt;&amp;nbsp;false positives may occur.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;When evaluating an event, all the intrusion chain should be evaluate.&lt;/P&gt;
&lt;P&gt;A single alert may happen either while browsing and get a redirection that force the resolution of a .pw dns query or if a malicious process is running on the host.&lt;/P&gt;
&lt;P&gt;First of all carefully check the rule content and confront it with your variable_set it might already vanish some doubts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your controller most likely is the DNS resolver as well that's why you get the alert from this host.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should identify the client that generate the query.&amp;nbsp;Once the client is identified, you could&amp;nbsp;investigate a bit deeper on this&amp;nbsp;host. If your network configuration doesn't give you visibility between client and dns&amp;nbsp;server you can setup a sinkhole.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again, don't focus on a single clue. &amp;nbsp;You should get a broader vision of your landscape.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's what analysts do.&lt;/P&gt;
&lt;P&gt;Last but not the least, remember that each managed device can be targeted by only one access control policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this can help!&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2016 21:24:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974086#M1019071</guid>
      <dc:creator>andrea.veltri1</dc:creator>
      <dc:date>2016-09-25T21:24:32Z</dc:date>
    </item>
    <item>
      <title>Thank you for advice! </title>
      <link>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974087#M1019072</link>
      <description>&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Thank you for advice!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;I have URL and malware&amp;nbsp;&amp;nbsp;subscription. Will I need to buy AMP&amp;nbsp;subscription?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 05:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-network-trojan-was-detected/m-p/2974087#M1019072</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-09-26T05:57:10Z</dc:date>
    </item>
  </channel>
</rss>

