<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Suspicious DNS Query (generic:omnatour.com) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-omnatour-com/m-p/455062#M101533</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JasonWindsor_0-1640199301289.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38325i5C3F836ECAB840DE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JasonWindsor_0-1640199301289.png" alt="JasonWindsor_0-1640199301289.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me if this is legitimate or if it's a false positive? My Cortex XDR hasn't found any behavioral issues to go along with it either.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Dec 2021 18:55:54 GMT</pubDate>
    <dc:creator>JasonWindsor</dc:creator>
    <dc:date>2021-12-22T18:55:54Z</dc:date>
    <item>
      <title>Suspicious DNS Query (generic:omnatour.com)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-omnatour-com/m-p/455062#M101533</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JasonWindsor_0-1640199301289.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38325i5C3F836ECAB840DE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JasonWindsor_0-1640199301289.png" alt="JasonWindsor_0-1640199301289.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me if this is legitimate or if it's a false positive? My Cortex XDR hasn't found any behavioral issues to go along with it either.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 18:55:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-omnatour-com/m-p/455062#M101533</guid>
      <dc:creator>JasonWindsor</dc:creator>
      <dc:date>2021-12-22T18:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:omnatour.com)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-omnatour-com/m-p/455093#M101536</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Here are a few sites I use to determine what is and what is not safe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;virustotal.com&lt;/P&gt;
&lt;P&gt;urlscan.io&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dnsdumpster.com/" target="_blank"&gt;https://dnsdumpster.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 19:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-omnatour-com/m-p/455093#M101536</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-22T19:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:omnatour.com)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-omnatour-com/m-p/455738#M101611</link>
      <description>&lt;P&gt;We have regularly seen this DNS alert as well, on random public Wifi users, though the threat ID seems to have been removed in the last couple weeks. omnatuor.com seems to be associated with adware, using the browser notification subscribe action to push popup ads via the browser. I would remove the subscriptions if found on your PCs as undesirable and a nuisance, but it doesn't seem to be actively hostile.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 18:11:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-omnatour-com/m-p/455738#M101611</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2021-12-28T18:11:45Z</dc:date>
    </item>
  </channel>
</rss>

