<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Finding Zeus Bot (Zbot) with Sophos UTM	</title>
	<atom:link href="https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/feed/" rel="self" type="application/rss+xml" />
	<link>https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/</link>
	<description>Share your knowledge!</description>
	<lastBuildDate>Mon, 17 Feb 2014 14:42:45 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>
	<item>
		<title>
		By: Michel		</title>
		<link>https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-157</link>

		<dc:creator><![CDATA[Michel]]></dc:creator>
		<pubDate>Mon, 17 Feb 2014 14:42:45 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=606#comment-157</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-156&quot;&gt;Guido Meijers&lt;/a&gt;.

Traffic with virus-infection is detected by Sophos UTM already, but we are speaking about malware, that communicate as a normal PC (for example a normal http connect to a server). Sophos UTM will be able to see this with hashes coming from the central Sophos cloud to recognize such traffic.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-156">Guido Meijers</a>.</p>
<p>Traffic with virus-infection is detected by Sophos UTM already, but we are speaking about malware, that communicate as a normal PC (for example a normal http connect to a server). Sophos UTM will be able to see this with hashes coming from the central Sophos cloud to recognize such traffic.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Guido Meijers		</title>
		<link>https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-156</link>

		<dc:creator><![CDATA[Guido Meijers]]></dc:creator>
		<pubDate>Mon, 17 Feb 2014 14:14:07 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=606#comment-156</guid>

					<description><![CDATA[Yes, i wonder why only now... Fortinet seems to do this for a while already (4 Years) :)
Not sure yet what to choose...]]></description>
			<content:encoded><![CDATA[<p>Yes, i wonder why only now&#8230; Fortinet seems to do this for a while already (4 Years) :)<br />
Not sure yet what to choose&#8230;</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Michel		</title>
		<link>https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-155</link>

		<dc:creator><![CDATA[Michel]]></dc:creator>
		<pubDate>Mon, 17 Feb 2014 13:20:38 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=606#comment-155</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-132&quot;&gt;Guido&lt;/a&gt;.

Hi Guido,

i think this packets will be blocked with the Advanced Threat Protection (ATP) in Version 9.2 coming March/April this year.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-132">Guido</a>.</p>
<p>Hi Guido,</p>
<p>i think this packets will be blocked with the Advanced Threat Protection (ATP) in Version 9.2 coming March/April this year.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Michel		</title>
		<link>https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-133</link>

		<dc:creator><![CDATA[Michel]]></dc:creator>
		<pubDate>Thu, 30 Jan 2014 13:19:03 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=606#comment-133</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-132&quot;&gt;Guido&lt;/a&gt;.

Hi Guido,

no it can&#039;t be recognize because it was a normal http request so there was no malware code within the tcp stream.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-132">Guido</a>.</p>
<p>Hi Guido,</p>
<p>no it can&#8217;t be recognize because it was a normal http request so there was no malware code within the tcp stream.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Guido		</title>
		<link>https://networkguy.de/finding-zeus-bot-zbot-with-sophos-utm/#comment-132</link>

		<dc:creator><![CDATA[Guido]]></dc:creator>
		<pubDate>Wed, 29 Jan 2014 13:44:55 +0000</pubDate>
		<guid isPermaLink="false">http://networkguy.de/?p=606#comment-132</guid>

					<description><![CDATA[Hi,  We are currently looking for a UTm and Sophos is on the shortlist. But why doesn&#039;t the UTM detect this and block the outgoing packets? This would the perfect Use Case for a UTm vs classic Firewall or not?]]></description>
			<content:encoded><![CDATA[<p>Hi,  We are currently looking for a UTm and Sophos is on the shortlist. But why doesn&#8217;t the UTM detect this and block the outgoing packets? This would the perfect Use Case for a UTm vs classic Firewall or not?</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
