<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocking Scammer website (cryptocurrency) in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558767#M2004</link>
    <description>&lt;P&gt;I stumbled accros this article on Bleeping Computers&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/tiktok-flooded-by-elon-musk-cryptocurrency-giveaway-scams/" target="_blank"&gt;https://www.bleepingcomputer.com/news/security/tiktok-flooded-by-elon-musk-cryptocurrency-giveaway-scams/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;To my surprise the URL's mentioned in the article where considered safe.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto had these categorized as for example&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Stock-Advice-and-Tools&lt;/LI&gt;
&lt;LI&gt;Low-Risk&lt;/LI&gt;
&lt;LI&gt;Newly-Registered-Domain&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So I figured I would block the &lt;STRONG&gt;newly-registered-domain&lt;/STRONG&gt; as these are often used by scammers or malicious users. They pop-up and disappear very frequently.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately that did not work. According to my logging the URL's are "not-resolved" and the domains itself appear to have a very short TTL (5 minutes)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only thing I could think of is to add these domains to my manual block list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So my question is basically, what can I do to block these sites in a pro-active way?&amp;nbsp;&lt;BR /&gt;These scammers appear to be pretty smart circumventing our safety systems.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts are more than welcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2023 12:06:35 GMT</pubDate>
    <dc:creator>Remko</dc:creator>
    <dc:date>2023-09-20T12:06:35Z</dc:date>
    <item>
      <title>Blocking Scammer website (cryptocurrency)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558767#M2004</link>
      <description>&lt;P&gt;I stumbled accros this article on Bleeping Computers&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/tiktok-flooded-by-elon-musk-cryptocurrency-giveaway-scams/" target="_blank"&gt;https://www.bleepingcomputer.com/news/security/tiktok-flooded-by-elon-musk-cryptocurrency-giveaway-scams/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;To my surprise the URL's mentioned in the article where considered safe.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto had these categorized as for example&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Stock-Advice-and-Tools&lt;/LI&gt;
&lt;LI&gt;Low-Risk&lt;/LI&gt;
&lt;LI&gt;Newly-Registered-Domain&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So I figured I would block the &lt;STRONG&gt;newly-registered-domain&lt;/STRONG&gt; as these are often used by scammers or malicious users. They pop-up and disappear very frequently.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately that did not work. According to my logging the URL's are "not-resolved" and the domains itself appear to have a very short TTL (5 minutes)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only thing I could think of is to add these domains to my manual block list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So my question is basically, what can I do to block these sites in a pro-active way?&amp;nbsp;&lt;BR /&gt;These scammers appear to be pretty smart circumventing our safety systems.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts are more than welcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 12:06:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558767#M2004</guid>
      <dc:creator>Remko</dc:creator>
      <dc:date>2023-09-20T12:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Scammer website (cryptocurrency)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558779#M2005</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222853"&gt;@Remko&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is interesting that your logs say "not-resolved", which means the NGFW was unable to connect to the cloud.&amp;nbsp; See row 37 in the following URL.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5hCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5hCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With normal cloud connectivity, you should be able to block the Unknown category (row 65) and URLs that have not been categorized should be blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is always a balance between security and availability, and there is the potential that blocking Unknown may negatively impact sanctioned browsing.&amp;nbsp; The table says that blocking Not-Resolved could be very disruptive.&amp;nbsp; We don't want all web sites blocked that are not cached when the NGFW loses connectivity to the cloud.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 12:35:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558779#M2005</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-20T12:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Scammer website (cryptocurrency)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558800#M2006</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interesting finding. Very helpful ! &lt;BR /&gt;I have never given this much thought as most websites are classified according to what is expected.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As it appears our Palo Alto is missing the last step described at #37&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Indicates that the website was not found in the local URL filtering database and the firewall was unable to connect to the cloud database to check the category. When a URL category lookup is performed, the firewall first checks the dataplane cache for the URL, if no match is found, it will then check the management plane cache, &lt;FONT color="#FF00FF"&gt;and if no match is found there, it queries the URL database in the cloud&lt;/FONT&gt;. When deciding on what action to take for traffic that is categorized as not-resolved, be aware that setting the action to block may be very disruptive to users.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;So the question that comes to mind is why it doesn't do the last step. Should this just work out-of-the-box or is it a setting that might be overlooked? Our device is able to do DNS queries just fine. I need to dig deeper to see if this is the case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remko&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 13:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558800#M2006</guid>
      <dc:creator>Remko</dc:creator>
      <dc:date>2023-09-20T13:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Scammer website (cryptocurrency)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558804#M2007</link>
      <description>&lt;P&gt;From what I understand is that the URL check works without configuration&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-basics/how-url-filtering-works" target="_blank"&gt;https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-basics/how-url-filtering-works&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;When I query the URL filtering site on PaloAltoNetworks it is classified as&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Remko_0-1695216188112.png" style="width: 556px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53884iF4A1CC3BBE67C1DF/image-dimensions/556x317/is-moderation-mode/true?v=v2" width="556" height="317" role="button" title="Remko_0-1695216188112.png" alt="Remko_0-1695216188112.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And the firewall gives the following&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Remko_1-1695216336628.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53885iB6F9A4EBC952D505/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Remko_1-1695216336628.png" alt="Remko_1-1695216336628.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am puzzled &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 13:28:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558804#M2007</guid>
      <dc:creator>Remko</dc:creator>
      <dc:date>2023-09-20T13:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Scammer website (cryptocurrency)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558805#M2008</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222853"&gt;@Remko&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Exactly!&amp;nbsp; What does "show url-cloud status" show?&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/advanced-url-filtering/administration/troubleshooting/pan-db-cloud-connectivity-issues" target="_blank"&gt;https://docs.paloaltonetworks.com/advanced-url-filtering/administration/troubleshooting/pan-db-cloud-connectivity-issues&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 13:29:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558805#M2008</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-20T13:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Scammer website (cryptocurrency)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558816#M2009</link>
      <description>&lt;P&gt;You might be onto something.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It shows "nothing"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Remko_0-1695217691373.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53887i7F2A16369917128C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Remko_0-1695217691373.png" alt="Remko_0-1695217691373.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently troubleshooting the ruleset. Unfortunately I need to leave from work and I will continue my efforts tomorrow.&amp;nbsp;&lt;BR /&gt;I appreciate the time and effort !&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Remko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 13:56:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558816#M2009</guid>
      <dc:creator>Remko</dc:creator>
      <dc:date>2023-09-20T13:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Scammer website (cryptocurrency)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558982#M2011</link>
      <description>&lt;P&gt;We noticed that it was some time ago that we had updated our Palo Alto.&amp;nbsp;&lt;BR /&gt;So this morning we updated both appliances and Voila.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cloud connection started working again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Remko_0-1695290533187.png" style="width: 562px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53917i6A706B97D1112EBA/image-dimensions/562x215/is-moderation-mode/true?v=v2" width="562" height="215" role="button" title="Remko_0-1695290533187.png" alt="Remko_0-1695290533187.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I still need to check the monitoring log but I believe we made some excellent progress.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again !&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 10:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558982#M2011</guid>
      <dc:creator>Remko</dc:creator>
      <dc:date>2023-09-21T10:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Scammer website (cryptocurrency)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558987#M2012</link>
      <description>&lt;P&gt;As expected the domain is now correctly recognized and clasified.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Remko_0-1695293497128.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53918i17BC0B90D82CF33B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Remko_0-1695293497128.png" alt="Remko_0-1695293497128.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Case closed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 13:12:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/blocking-scammer-website-cryptocurrency/m-p/558987#M2012</guid>
      <dc:creator>Remko</dc:creator>
      <dc:date>2023-09-21T13:12:23Z</dc:date>
    </item>
  </channel>
</rss>

