<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tons of receptivity.io in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/595239#M7085</link>
    <description>&lt;P&gt;Now I have the root domain showing up in my logs as parked and thus in my threat logs.&lt;/P&gt;
&lt;P&gt;I asked them to recategorize that one as well, and instantly sad no. Time to have another 2 month battle with PAN support. Thanks PAN I love you guys, very helpful and the stress you cause me should be a crime against humanity.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2024 15:20:13 GMT</pubDate>
    <dc:creator>Zewwy</dc:creator>
    <dc:date>2024-08-19T15:20:13Z</dc:date>
    <item>
      <title>Tons of receptivity.io</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/584532#M6560</link>
      <description>&lt;P&gt;I recently see a lot of my end machine shitting this domain:&amp;nbsp;&lt;SPAN&gt;receptivity.io&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Started (I dunno even know, a week ago?) My logs can no longer go far enough back to figure it out.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cause I dunno, MS edge new tab? To hopefully remove the log entries I changed our new page to open our corporate homepage instead. PAN URL Checker states its a parked domain.&amp;nbsp;&lt;A href="https://urlfiltering.paloaltonetworks.com/query/" target="_blank"&gt;Palo Alto Networks URL filtering - Test A Site&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If it is parked why are so many of my machines trying to reach it?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 20:31:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/584532#M6560</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2024-04-22T20:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: Tons of receptivity.io</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/585074#M6605</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33952"&gt;@Zewwy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;In order to analyse network activity you can take help from "network_story" present in XQL query builder. You can filter out traffic specific to this domain with field like dns_query. Additionally if you are ingesting your firewall logs into XDR then you can easily query network traffic and correlate the events to find the root cause.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 15:00:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/585074#M6605</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-04-26T15:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Tons of receptivity.io</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/588268#M6756</link>
      <description>&lt;P&gt;While I fully understand the reasoning behind your response, it in reality is not helpful. (*EDIT/UPDATE* I just noticed this thread has been created/ or moved in the Cortex XDR topic area, I do not remember picking this). Everything in your response assumes XDR is already in place, in your example '&lt;SPAN&gt;"network_story" present in XQL query builder' is only available in Cortex. See:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-an-XQL-Query" target="_blank" rel="noopener"&gt;Create an XQL Query • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Then you simply follow up with stating using an XDR to build a timeline. Again, technically correct answers, but they are vague and lack any actual helpful insights when the assumptions are not fulfilled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What we did end up doing was using IPinfo, and other online tools to do diagnostics on the domains IPs, and with their Passive DNS options we were able to determine what sites/services are using the said domain. In this case, it was a local new agency, hence why it keeps poping up all the time, also with DNS sec by Palo Alto Network relies on URL categorizations, which in the case the domain as seen by Palo Alto Networks is "Parked Domain".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I can't find any front facing public websites to denote what this domain provides a service for, which to me raises red flags. Does anyone out there provide other real help information about this domain, who are they, what do they do? The best I could find was a whois which showed the domain registered in 2021 via GoDaddy, and all other info is redacted "for privacy".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anyone else with any other insight, I would greatly appreciated it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 14:42:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/588268#M6756</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2024-05-29T14:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Tons of receptivity.io</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/588838#M6789</link>
      <description>&lt;P&gt;I'm starting to get extremely frustrated at this problem. I did all the analytical work and NO ONE is helping!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) This pops up in our firewall flooding our threat log. Why cause parked domains is part of your DNS security to be sinkholed. The domain in question is&amp;nbsp;&lt;SPAN&gt;receptivity.io&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;2) Either using XDR queries on end machines, or Passive DNS on the destination IP addresses. Both indicated that it's due to user's navigating to CBC (&lt;SPAN&gt;Canadian Broadcasting Corporation)&lt;/SPAN&gt;&amp;nbsp;website (cbc.ca). You can verify this by opening your web browser and opening the dev tools (f12), navigate to cbc.ca, then in the HTML code search for "&lt;SPAN&gt;receptivity.io" and you will find it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) I've reached out to my local SE, and he didn't know what the domain was, and used ChatGPT which told him it's for "eptivity.io is a platform that provides marketing automation solutions. It helps businesses streamline their marketing efforts by automating tasks such as email marketing, lead generation, and customer segmentation. The platform aims to improve customer engagement and increase conversion rates through personalized and targeted marketing campaigns".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;If this is case then, how is it possible this domain has no public facing website to sell said service?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;I asked my SE if ChatGPT at any citation to source the information and I have not got a reply back.&lt;BR /&gt;4) I've attempted to reach out to CBC to ask if this service is legit, and if so, how are they using it, and how did they discover the service to use in the first place if there's no public facing website.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5) There appears to be a public website for&amp;nbsp;&lt;/SPAN&gt;Receptiviti.com, which appears to be completely unrelated.&lt;/P&gt;
&lt;P&gt;6) I put in a request to PAN URL categorization to get it recatgorized, and if it's legit I'd assume the tech team that handles that has some better tools and techniques to do proper categorizations. But they simply reported back that they are leaving it as parked.&lt;BR /&gt;"&lt;/P&gt;
&lt;P&gt;URL: receptivity[.]io&lt;/P&gt;
&lt;P&gt;Previous category: parked&lt;/P&gt;
&lt;P&gt;You suggested: malware&lt;/P&gt;
&lt;P&gt;New category: parked&lt;/P&gt;
&lt;P&gt;The new categorization is available starting with URL DB version: 20240603.20358"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why can I not get ANY help on this?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:31:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/588838#M6789</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2024-06-05T14:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Tons of receptivity.io</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/588929#M6799</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33952"&gt;@Zewwy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This forum is for XDR product related discussions. Analysis of a domain and its reputation is out of scope for this forum.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please raise a support case to help you with the investigation.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 09:52:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/588929#M6799</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-06-06T09:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Tons of receptivity.io</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/589811#M6831</link>
      <description>&lt;P&gt;Thanks Nsinghvirk,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I was hoping as a community that there would be an appropriate thread topic to which discuss these matters, if this was not the one after initial creation, I was second hoping there would be forum moderators that could move the thread to a more appropriate area to get correct attention and help a Original Poster is seeking.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is not a community driven forum, then ask me to leave, and I will gladly leave this forum site forever.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having said that, we did further investigation on the domain and source, and contact the Canadian Cyber Security and they provided us with the following additional details about the domain in question:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;P&gt;I received the following answer relating to your enquiry from our Cyber Incident team:&lt;/P&gt;
&lt;P&gt;This api call is viewed by checking the CBC.ca page source:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="cbc source.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60396iDCF18A08A991A463/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cbc source.png" alt="cbc source.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The company responsible for this api is Contxtful Technologies Inc: &lt;A href="https://documentation.contxtful.com/space/DOCS2020/1040646377/Contxtful's+Data+Approach" target="_blank"&gt;https://documentation.contxtful.com/space/DOCS2020/1040646377/Contxtful's+Data+Approach&lt;/A&gt;&lt;BR /&gt;The gist of it is that it collects mobile sensor data to use it for machine learning of user interactivity with ads. Basically, a fancy collector of data to target ads better.&lt;BR /&gt;The amount of pings on their firewall must be due to it being related to ads and data collection.&lt;BR /&gt;This api call has also been seen at other news article websites as well."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have forwarded this information on to the PAN category team, but every time I make a request to change the category to web-advertisements they come back stating it will remained parked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My questions now are:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) How can I get this thread moved to a new topic area?&lt;BR /&gt;2) How can I get the PAN URL category team to actually change the type based on these findings?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 14:13:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/589811#M6831</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2024-06-18T14:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Tons of receptivity.io</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/595238#M7084</link>
      <description>&lt;P&gt;After 2 months, PAN finally decided to change the category. Yay... Thanks PAN.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 15:02:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/595238#M7084</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2024-08-19T15:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: Tons of receptivity.io</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/595239#M7085</link>
      <description>&lt;P&gt;Now I have the root domain showing up in my logs as parked and thus in my threat logs.&lt;/P&gt;
&lt;P&gt;I asked them to recategorize that one as well, and instantly sad no. Time to have another 2 month battle with PAN support. Thanks PAN I love you guys, very helpful and the stress you cause me should be a crime against humanity.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 15:20:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tons-of-receptivity-io/m-p/595239#M7085</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2024-08-19T15:20:13Z</dc:date>
    </item>
  </channel>
</rss>

