<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secshow.net in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/563074#M5422</link>
    <description>&lt;P&gt;Hi &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/324251"&gt;@ade.reza&lt;/a&gt;&lt;/SPAN&gt; , &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/259628"&gt;@amjadkhan&lt;/a&gt;&lt;/SPAN&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you shared a screenshot of the detailed log view?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2023 06:58:53 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2023-10-25T06:58:53Z</dc:date>
    <item>
      <title>Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/562661#M5394</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you help for information i need&lt;/P&gt;
&lt;P&gt;attach the picture.&lt;/P&gt;
&lt;P&gt;what are the meaning thread id tunneling:secshow.net ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1000003980.jpg" style="width: 1138px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54609i9FD736BBFC31C602/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="1000003980.jpg" alt="1000003980.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2023 04:18:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/562661#M5394</guid>
      <dc:creator>ade.reza</dc:creator>
      <dc:date>2023-10-22T04:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/562700#M5397</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am getting the same threat log with Threat ID tunneling: secshow.net. and continuously sinkhole the traffic. If anyone can help identifying what is that.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 05:54:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/562700#M5397</guid>
      <dc:creator>amjadkhan</dc:creator>
      <dc:date>2023-10-23T05:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/563074#M5422</link>
      <description>&lt;P&gt;Hi &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/324251"&gt;@ade.reza&lt;/a&gt;&lt;/SPAN&gt; , &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/259628"&gt;@amjadkhan&lt;/a&gt;&lt;/SPAN&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you shared a screenshot of the detailed log view?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 06:58:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/563074#M5422</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-10-25T06:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/567350#M5619</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;&lt;BR /&gt;I have the same problem, any updates ?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 07:44:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/567350#M5619</guid>
      <dc:creator>Faraculla_azizli</dc:creator>
      <dc:date>2023-11-28T07:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/567407#M5621</link>
      <description>&lt;P&gt;Same problem here also. The other strange part is, that they typically occur from one of my external IP's going to another of my external IP's.&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;   Domain Name: SECSHOW.NET
   Registry Domain ID: 2793806009_DOMAIN_NET-VRSN
   Registrar WHOIS Server: grs-whois.hichina.com
   Registrar URL: http://wanwang.aliyun.com
   Updated Date: 2023-06-27T02:10:51Z
   Creation Date: 2023-06-27T02:07:57Z
   Registry Expiry Date: 2024-06-27T02:07:57Z
   Registrar: Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn)
   Registrar IANA ID: 1599
   Registrar Abuse Contact Email: DomainAbuse@service.aliyun.com
   Registrar Abuse Contact Phone: +86.95187
   Domain Status: ok https://icann.org/epp#ok
   Name Server: DNS23.HICHINA.COM
   Name Server: DNS24.HICHINA.COM
   DNSSEC: unsigned
   URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
&amp;gt;&amp;gt;&amp;gt; Last update of whois database: 2023-11-28T14:47:52Z &amp;lt;&amp;lt;&amp;lt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 28 Nov 2023 14:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/567407#M5621</guid>
      <dc:creator>jasonwald</dc:creator>
      <dc:date>2023-11-28T14:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/567490#M5624</link>
      <description>&lt;P&gt;Unfortunately, in my case, local host is behind NAT, so that I cannot see either Source User or machine IP or MAC.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 05:47:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/567490#M5624</guid>
      <dc:creator>Faraculla_azizli</dc:creator>
      <dc:date>2023-11-29T05:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/569750#M5729</link>
      <description>&lt;P&gt;secshow.net and secshow.online DNS traffic happening for us too, public IP to Public IP. The URLs not matching with typical syntax for DNS tunnelling so I don't think that's what's happening. One domain owned by alibaba.&lt;BR /&gt;&lt;BR /&gt;Ever since the upgrade in October to&amp;nbsp;&lt;SPAN&gt;10.1.11 this has been happening - did not see any patch notes about this or DNS. Many changes though in this release.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Upgrading to 1&lt;SPAN&gt;0.2.7 soon and wondering if this will fix it.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp; - if palo has any updates or communications for their customers about this it would be great. Seems like a widespread issue that hasn't been communicated. Given that this is setting off security alerts some sort of note would be great that Palo is at least aware if this is a bug and is working on a fix.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 17:36:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/569750#M5729</guid>
      <dc:creator>TylerMuch</dc:creator>
      <dc:date>2023-12-13T17:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/569794#M5730</link>
      <description>&lt;P&gt;Unfortunately 10.2.7 does not fix this. It is still going strong on my 450's with 10.2.7&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 22:23:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/569794#M5730</guid>
      <dc:creator>jasonwald</dc:creator>
      <dc:date>2023-12-13T22:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/573781#M5914</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128435"&gt;@jasonwald&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;we are having similar looking issue. Is there any progress finding out where such traffic is coming from?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2024 09:31:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/573781#M5914</guid>
      <dc:creator>Andreikin</dc:creator>
      <dc:date>2024-01-20T09:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/573801#M5915</link>
      <description>&lt;P&gt;I'm not a Palo Alto user, but I've been receiving this traffic for several months. It appears to be someone spoofing an adjacent source address while making DNS queries to every IPv4 address, and checking which IPs end up forwarding the query to a recursive resolver. Presumably the goal is to find open resolvers for DNS amplification attacks or similar. The hex string in the secshow.net DNS name corresponds with the IP address being spoofed, and I've been messing with their results by making DNS queries for random IPs whenever the spoofer is active. It appears to be working, as they've ramped up the frequency of scans, and made some modifications to the hostname format. Hopefully they'll give up soon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't received any traffic for secshow.online, interestingly.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 00:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/573801#M5915</guid>
      <dc:creator>antispoof</dc:creator>
      <dc:date>2024-01-21T00:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/582040#M6435</link>
      <description>&lt;P&gt;This seems to be going strong again within the last few days. Super annoying. Would love to get some more info on this.&lt;/P&gt;
&lt;P&gt;threatid: Tunneling:secshow.net(109001001)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 13:30:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/582040#M6435</guid>
      <dc:creator>jasonwald</dc:creator>
      <dc:date>2024-03-28T13:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/582063#M6436</link>
      <description>&lt;P&gt;I can confirm that it seems to be back.&amp;nbsp; In addition to secshow.net, there's also now a "savme.xyz" producing the same type of traffic.&amp;nbsp; Someone did a write-up on it here:&amp;nbsp;&lt;A href="https://dataplane.substack.com/p/destination-adjacent-source-address" target="_blank"&gt;https://dataplane.substack.com/p/destination-adjacent-source-address&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 20:19:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/582063#M6436</guid>
      <dc:creator>antispoof</dc:creator>
      <dc:date>2024-03-28T20:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Secshow.net</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/582064#M6437</link>
      <description>&lt;P&gt;Thank you for sharing this.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 20:29:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/secshow-net/m-p/582064#M6437</guid>
      <dc:creator>jasonwald</dc:creator>
      <dc:date>2024-03-28T20:29:04Z</dc:date>
    </item>
  </channel>
</rss>

