Why am I seeing two Anti-Virus signatures triggered for one file when WF real-time is enabled

Why am I seeing two Anti-Virus signatures triggered for one file when WF real-time is enabled

263
Created On 03/06/23 23:37 PM - Last Modified 11/06/25 20:48 PM


Question


Why am I seeing two anti-virus signatures triggered for one file when WF real-time is enabled?Screen Shot 2023-03-06 at 3.27.33 PM.png
 


Environment


PAN-OS 10.0 and above

Answer


This is due to combinations of a few scenarios, including (a) enabling WF real-time setting on Firewall, (b) and a signature in replace status.  
  • Firewall Wildfire real-time is enabled. 
image.png
  • Example: Signature with 305248623, status is 'replace' and has two hashes associated with it.
    • a9beed803dc58e06d278e593ec5c5619bdce4b45ec6d8e1697957e9923612711
    • 435052fec38434281ade35a0171d6f352fe44e905552b1ca40839df74e5ddbcb
  • image.png
  • When a sample is pushed again through Firewall, 6dab5a397b97b2604d9d7541f02e7548de34e1c53b359263583c0fe0407b5827, a new signature is generated with TID: 574021117 on 03/02/2023 13:08 PST. Patterns: f2b43291000000000001682900016962000169dbb9e3f455
  • debug dataplane show ctd wf-cache virus-pattern-type ALL
    Virus Pattern (hex encoded): f2b43291000000000001682900016962000169dbb9e3f455
    UTID: 574021117, NPatterns: 1, PatternPos: 0, Disabled: No
    
      Since the real-time WF setting, a cloud query will receive the signature information, and Firewall MP and DP cache will be populated. 
  • Virus Pattern (hex encoded): 7064660000000000000000000001706b0000000000000000
    UTID: 305248623, NPatterns: 1, PatternPos: 0, Disabled: No
    
    Both signatures have different patterns, however it will trigger on the same file. 
  • Once the new signature is generated, the old hash is removed from the previous TID ( even for PDFs)

Both Signatures:
 

admin@PA-VM> debug dataplane show ctd wf-cache virus-pattern-type ALL 

Virus Pattern (hex encoded): 050ace0063fe058b00067cab000000000011400060064200
UTID: 573910297, NPatterns: 1, PatternPos: 0, Disabled: Yes

Virus Pattern (hex encoded): f2b43291000000000001682900016962000169dbb9e3f455
UTID: 574021117, NPatterns: 1, PatternPos: 0, Disabled: No

Virus Pattern (hex encoded): 7064660000000000000000000001706b0000000000000000
UTID: 305248623, NPatterns: 1, PatternPos: 0, Disabled: No

Virus Pattern (hex encoded): 6830316bcddcdccdaaeeccffcddcdccdaaeeccffdeadbeef
UTID: 157123251, NPatterns: 1, PatternPos: 0, Disabled: Yes

 



Additional Information


When the new signature is generated, the sample from the old one is removed. 

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kHESCA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail