<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spyware with DNS Protection in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/333566#M856</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34186"&gt;@mivaldi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That's good ideas. I have a rules for blocked APT with malware url. Threat stopped when i disabled it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So many thanks&lt;/P&gt;&lt;P&gt;Khai&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jun 2020 02:06:20 GMT</pubDate>
    <dc:creator>Khai-Huynh</dc:creator>
    <dc:date>2020-06-16T02:06:20Z</dc:date>
    <item>
      <title>Spyware with DNS Protection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/331261#M840</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Our Firewall drop DNS traffic of C&amp;amp;C (&amp;nbsp;us.jaxonsorensen.club, news.sqllitlerver.info &amp;amp; log.osloger.biz) with source IP Address of Firewall. This issue after update the Threat 28/05/2020.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Will appreciate any help/suggestions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Khai&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 05:00:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/331261#M840</guid>
      <dc:creator>Khai-Huynh</dc:creator>
      <dc:date>2020-06-03T05:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware with DNS Protection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/331430#M842</link>
      <description>&lt;P&gt;This can be caused by the firewall running DNS proxy, or attempting to fill out the IP information in pre-defined threat reports. Check your Threat logs to see if these domains have been observed, and verify the threat reports to see if any generated reporting the malicious domain findings.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 16:22:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/331430#M842</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-06-03T16:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware with DNS Protection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/331546#M844</link>
      <description>&lt;P&gt;Thanks Mivaldi,&lt;/P&gt;&lt;P&gt;The problem here, I didn't configuration about the DNS Proxy. I checked all host in our network nothing query to spyware DNS. Only Firewall Palo alto request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Khai&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 02:11:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/331546#M844</guid>
      <dc:creator>Khai-Huynh</dc:creator>
      <dc:date>2020-06-04T02:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware with DNS Protection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/331662#M845</link>
      <description>&lt;P&gt;Check your URL Filtering logs.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 16:51:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/331662#M845</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-06-04T16:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware with DNS Protection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/333315#M851</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested these and see that PA blocks them under threat as type spyware.&lt;/P&gt;&lt;P&gt;Source address is my PC and it is working as expected as i have dns sinkhole configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will not see any traffic for these sites under url as it sinkholed.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jun 2020 18:47:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/333315#M851</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-06-13T18:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware with DNS Protection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/333530#M853</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;I think you got lost in the train of thought.&amp;nbsp;&lt;/SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138704"&gt;@Khai-Huynh&lt;/a&gt;&lt;SPAN style="font-family: inherit;"&gt;&amp;nbsp;is saying that the DNS sinkhole actions are showing up for traffic where the firewall management IP is the source of the DNS queries.&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138704"&gt;@Khai-Huynh&lt;/a&gt;&amp;nbsp;is hinting that the firewall could be compromised since there should not be a reason for it to source queries to malicious domains. What I am saying here is that this is not a sign of a compromised firewall, since queries to malicious domains may happen when the firewall generates Threat Reports. Some of these threat reports are based on URL Filtering malware category detections (for example), and the firewall will source a DNS query to fill out IP address information in the Threat Reports (that may subsequently get caught in the Anti-Spyware DNS profile).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 20:43:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/333530#M853</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-06-15T20:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Spyware with DNS Protection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/333566#M856</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34186"&gt;@mivaldi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That's good ideas. I have a rules for blocked APT with malware url. Threat stopped when i disabled it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So many thanks&lt;/P&gt;&lt;P&gt;Khai&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 02:06:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/spyware-with-dns-protection/m-p/333566#M856</guid>
      <dc:creator>Khai-Huynh</dc:creator>
      <dc:date>2020-06-16T02:06:20Z</dc:date>
    </item>
  </channel>
</rss>

