<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting Inbound connections from Malicious Palo Alto IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/getting-inbound-connections-from-malicious-palo-alto-ip/m-p/997878#M122514</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/327952965"&gt;@ganapatimajhi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I would actually say this isn't really that abnormal. Due to scanning (to help categorize websites properly) it isn't abnormal for my various networks/clients to identify traffic against PAN maintained addresses and our automation to step in and deny the traffic. It's pretty common when we spin up new services to see an increase in traffic.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2024 22:30:28 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2024-12-11T22:30:28Z</dc:date>
    <item>
      <title>Getting Inbound connections from Malicious Palo Alto IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-inbound-connections-from-malicious-palo-alto-ip/m-p/997455#M122478</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;&lt;BR /&gt;I've recently detected inbound traffic from an IP address&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;147.185.132.201 &lt;/STRONG&gt;where the ISP is showing as&amp;nbsp;&lt;STRONG&gt;Palo Alto Networks, Inc&lt;/STRONG&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&amp;nbsp;&lt;BR /&gt;The IP has a malicious reputation over VT, AbuseIPDB, and IPVoid.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Can anyone with information about this IP address share their insights? Have you noticed any unusual activity associated with this IP? Are there any known affiliations or activities that could shed light on why it might be flagged?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 11:06:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-inbound-connections-from-malicious-palo-alto-ip/m-p/997455#M122478</guid>
      <dc:creator>ganapatimajhi</dc:creator>
      <dc:date>2024-12-10T11:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Inbound connections from Malicious Palo Alto IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-inbound-connections-from-malicious-palo-alto-ip/m-p/997516#M122483</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/327952965"&gt;@ganapatimajhi&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hello all,&lt;BR /&gt;&lt;BR /&gt;I've recently detected inbound traffic from an IP address&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;147.185.132.201 &lt;/STRONG&gt;where the ISP is showing as&amp;nbsp;&lt;STRONG&gt;Palo Alto Networks, Inc&lt;/STRONG&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&amp;nbsp;&lt;BR /&gt;The IP has a malicious reputation over VT, AbuseIPDB, and IPVoid.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Can anyone with information about this IP address share their insights? Have you noticed any unusual activity associated with this IP? Are there any known affiliations or activities that could shed light on why it might be flagged?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Kinda odd, who is shows it being actually a part of GPC, but Palo Alto.&amp;nbsp; I know Palo's primary cloud services are hosted in GPC.&amp;nbsp; I'm not sure what component of Palo's cloud service offering this IP would be coming from.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Brandon_Wertz_0-1733851171658.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64593i3B1F1AB0150D11CA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Brandon_Wertz_0-1733851171658.png" alt="Brandon_Wertz_0-1733851171658.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looks like this is the email to report abuse, or if you're a palo customer I'd say open a ticket:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Brandon_Wertz_1-1733851225578.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64594i97B55D658B1F3CD9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Brandon_Wertz_1-1733851225578.png" alt="Brandon_Wertz_1-1733851225578.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 17:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-inbound-connections-from-malicious-palo-alto-ip/m-p/997516#M122483</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-12-10T17:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Inbound connections from Malicious Palo Alto IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-inbound-connections-from-malicious-palo-alto-ip/m-p/997878#M122514</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/327952965"&gt;@ganapatimajhi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I would actually say this isn't really that abnormal. Due to scanning (to help categorize websites properly) it isn't abnormal for my various networks/clients to identify traffic against PAN maintained addresses and our automation to step in and deny the traffic. It's pretty common when we spin up new services to see an increase in traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 22:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-inbound-connections-from-malicious-palo-alto-ip/m-p/997878#M122514</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-12-11T22:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Inbound connections from Malicious Palo Alto IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-inbound-connections-from-malicious-palo-alto-ip/m-p/997945#M122520</link>
      <description>&lt;P&gt;As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; says, PaloAlto scans seen websites for URL categorization. On my own website, I had never seen this in my logs until I went to it from behind a PA and my site has subsequently been surveyed frequently. This is normally a few pulls of base pages, similar to any other web spider (about 20 per week). I have never seen path traversal attempt, variable injection, or other common signs of malicious activity. A typical scan looks like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;147.185.132.25 - - [11/Dec/2024:03:29:52 -0700] "GET / HTTP/1.1" 200 42 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers&amp;amp;#39; presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The scans come from:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;35.203.210.0/23 - GoogleCloud&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;147.185.132.0/23 - PaloAltoNetworks&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;162.216.149.0/24 - GoogleCloud&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;162.216.150.0/24 - GoogleCloud&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;198.235.24.0/24 - PaloAltoNetworks&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;205.210.31.0/24 - PaloAltoNetworks&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 02:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-inbound-connections-from-malicious-palo-alto-ip/m-p/997945#M122520</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-12-12T02:53:40Z</dc:date>
    </item>
  </channel>
</rss>

