<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Microsoft URL being DNS sinkholed suddenly? in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332165#M846</link>
    <description>&lt;P&gt;Has anyone else started getting DNS sinkhole threat alerts for the below domain? About half a day ago I started getting a tonne of sinkhole alarms from our PA for this URL. It looks to be a legitimate Microsoft domain and IP. In the PA threat log it comes up as Spyware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;skypedataprdcolase04.cloudapp.net&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA threat vault shows the below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BStojceski_0-1591526540792.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26124iC8512D2EA4D7C8A0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BStojceski_0-1591526540792.png" alt="BStojceski_0-1591526540792.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Anyone else seeing this and any word of why it is happening? I'm getting alerts all day and from a whole lot of different internal hosts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 07 Jun 2020 10:43:19 GMT</pubDate>
    <dc:creator>BStojceski</dc:creator>
    <dc:date>2020-06-07T10:43:19Z</dc:date>
    <item>
      <title>Microsoft URL being DNS sinkholed suddenly?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332165#M846</link>
      <description>&lt;P&gt;Has anyone else started getting DNS sinkhole threat alerts for the below domain? About half a day ago I started getting a tonne of sinkhole alarms from our PA for this URL. It looks to be a legitimate Microsoft domain and IP. In the PA threat log it comes up as Spyware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;skypedataprdcolase04.cloudapp.net&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA threat vault shows the below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BStojceski_0-1591526540792.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26124iC8512D2EA4D7C8A0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BStojceski_0-1591526540792.png" alt="BStojceski_0-1591526540792.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Anyone else seeing this and any word of why it is happening? I'm getting alerts all day and from a whole lot of different internal hosts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 10:43:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332165#M846</guid>
      <dc:creator>BStojceski</dc:creator>
      <dc:date>2020-06-07T10:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft URL being DNS sinkholed suddenly?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332177#M847</link>
      <description>&lt;P&gt;Same here, alerting around every 10 to 15 minutes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 13:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332177#M847</guid>
      <dc:creator>mbrimberry</dc:creator>
      <dc:date>2020-06-07T13:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft URL being DNS sinkholed suddenly?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332190#M848</link>
      <description>&lt;P&gt;i have got the same&amp;nbsp; thing to today , was it solved from your end .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all seem legit for me .&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 20:21:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332190#M848</guid>
      <dc:creator>xfahad</dc:creator>
      <dc:date>2020-06-07T20:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft URL being DNS sinkholed suddenly?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332194#M849</link>
      <description>&lt;P&gt;It seemed to eventually stop itself overnight. I did notice the threat ID disappeared from the threat DB a couple of hours before my post, so maybe it took time for the PA's to sync and stop triggering alerts? Seems to be OK now.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 21:56:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332194#M849</guid>
      <dc:creator>BStojceski</dc:creator>
      <dc:date>2020-06-07T21:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft URL being DNS sinkholed suddenly?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332373#M850</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The DNS Security signature was disabled on 06/05/2020 14:22 PDT, and the Anti-Spyware DNS signature is no longer present with 06/07's release of the Antivirus package version 3372-3883. Please upgrade to this version (or later) to have the signature removed.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 17:12:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-url-being-dns-sinkholed-suddenly/m-p/332373#M850</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-06-08T17:12:38Z</dc:date>
    </item>
  </channel>
</rss>

