<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspicious DNS Query Pan-DB and BrightCloud in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18751#M13660</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Obor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find Virus Total analysis for web site &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;.haalmeeruitjecard.nl, it confirms its not malicious.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/url/d1c543973051a69a9cf2c1f220b1e183bc0d7e434a78051adccf54a7a15740fe/analysis/1411477574/" title="https://www.virustotal.com/en/url/d1c543973051a69a9cf2c1f220b1e183bc0d7e434a78051adccf54a7a15740fe/analysis/1411477574/"&gt;Scan report for http://haalmeeruitjecard.nl/ at2014-09-23 13:06:14 UTC - VirusTotal&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure your are on latest content. If issue still occurs than please open a case with TAC for false positive. They should fix it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Changes will be reflected in next couple of days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Sep 2014 13:08:39 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-09-23T13:08:39Z</dc:date>
    <item>
      <title>Suspicious DNS Query Pan-DB and BrightCloud</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18749#M13658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using the BrightCloud URL DB for URL Filtering. Last week we had discovered an issue that users can’t access the URL http(s)://www.haalmeeruitjecard.nl &lt;/P&gt;&lt;P&gt;Searching the PaloAlto we see that is not blocked by the URL Log. BrightCloud says as URL Category “business-and-economy” and that is allowed.&lt;/P&gt;&lt;P&gt;Still the session can’t be setup and we did not see any block page at all.&lt;/P&gt;&lt;P&gt;Further looking we discovered that is blocked by the Anti-Spyware Rule with the Suspicious DNS Query action. We block Suspicious DNS Query query’s.&lt;/P&gt;&lt;P&gt;In the Thread log was reported : Suspicious DNS Query (www.haalmeeruitjecard.nl)!! Uuh this is a normal site here in the Netherlands.&lt;/P&gt;&lt;P&gt;So is it the Threat DB that this is causing??? NO, found out that the URL is marked in the PAN-DB Url Database as malware.&lt;/P&gt;&lt;P&gt;Requested a change for Pan-DB and after this was changed we had no more Suspicious DNS Query’s&amp;nbsp; for this url.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL: www.haalmeeruitjecard.nl&lt;/P&gt;&lt;P&gt;Previous category: malware&lt;/P&gt;&lt;P&gt;You suggested: financial-services&lt;/P&gt;&lt;P&gt;New category: financial-services&lt;/P&gt;&lt;P&gt;The new categorization is available starting with URL DB version: 2014.09.22.221&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean that the PaloAlto Device is using both URL database’s to provide protection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it than maybe better to migrate to PAN-DB URL Database so that all information is provided from 1 DB?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your responses.&lt;/P&gt;&lt;P&gt;Osman Bor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 07:03:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18749#M13658</guid>
      <dc:creator>obor</dc:creator>
      <dc:date>2014-09-23T07:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query Pan-DB and BrightCloud</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18750#M13659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Osman,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN firewall is having multiple layer of protection on it. Example: The content/packet will be inspected by:&lt;/P&gt;&lt;P&gt;--- URL filtering database &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;Bright Cloud or PAN DB) for categorization.&lt;/P&gt;&lt;P&gt;--- Application &amp;amp; Threat database for Vulnerability/DNS signature checking.&lt;/P&gt;&lt;P&gt;--- Antivirus database for virus /ANtispyware checking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if any packet identified with malicious in nature, will be blocked by&amp;nbsp; the above mentioned database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 07:47:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18750#M13659</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-23T07:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query Pan-DB and BrightCloud</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18751#M13660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Obor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find Virus Total analysis for web site &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;.haalmeeruitjecard.nl, it confirms its not malicious.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/url/d1c543973051a69a9cf2c1f220b1e183bc0d7e434a78051adccf54a7a15740fe/analysis/1411477574/" title="https://www.virustotal.com/en/url/d1c543973051a69a9cf2c1f220b1e183bc0d7e434a78051adccf54a7a15740fe/analysis/1411477574/"&gt;Scan report for http://haalmeeruitjecard.nl/ at2014-09-23 13:06:14 UTC - VirusTotal&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure your are on latest content. If issue still occurs than please open a case with TAC for false positive. They should fix it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Changes will be reflected in next couple of days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 13:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18751#M13660</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-23T13:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query Pan-DB and BrightCloud</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18752#M13661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Osman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you are right, PA firewall uses both DB to protect your network. In your example, even though brightcloud categorizes the traffic as business-and-economy, URL in question was categorized as suspicious by PANDB (which turned out to be false positive in this case) and was blocked by our Spyware engine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Migrating to PANDB might be a good option as we have total control over it, resulting in faster resolution for URL DB issues. Hope that helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 20:53:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18752#M13661</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-09-23T20:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query Pan-DB and BrightCloud</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18753#M13662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it correct what your saying and with the answer of ssharma it looks like this now:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;--- URL filtering database &lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;( &lt;/SPAN&gt;Bright Cloud or PAN DB) for categorization.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;--- Application &amp;amp; Threat database &amp;amp; &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;PAN DB&lt;/SPAN&gt; for Vulnerability/DNS signature checking.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;--- Antivirus database for virus /ANtispyware checking.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Regards,&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Osman Bor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 09:32:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-pan-db-and-brightcloud/m-p/18753#M13662</guid>
      <dc:creator>obor</dc:creator>
      <dc:date>2014-09-24T09:32:23Z</dc:date>
    </item>
  </channel>
</rss>

