<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sinkhole explosion in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19035#M13864</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Haverstad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;There is a large number of changes made on the recent Antivirus database version, regarding DNS signature. Almost 80,000 new DNS signatures has been added to this database. Could you please let me know the AV version currently installed on your PAN firewall. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Jan 2015 16:35:52 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2015-01-27T16:35:52Z</dc:date>
    <item>
      <title>Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19032#M13861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since midday yesterday (Monday Jan 26th) we've seen an explosion in sinkhole detections.&lt;BR /&gt;Previous moths sees one ot two a day in average, latest 24 hrs we've had more than 16.000 detections. This started after the antivirusupdate on Monday.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;When checki&lt;/SPAN&gt;ng a few of the domains via on-line URL-checking tools, no suspicious content is detected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latest antivirus signature contained a lot of Suspicious DNS adresses, but none of 'ours'&lt;/P&gt;&lt;P&gt;Has anyone else seen this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All DNS requests are blocked so no dangerous situation &lt;SPAN style="font-size: 13.3333330154419px;"&gt;appears&lt;/SPAN&gt;, but we suspect most of these requests to be false positive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone at PaloAlto check on this please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 12:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19032#M13861</guid>
      <dc:creator>pivvre</dc:creator>
      <dc:date>2015-01-27T12:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19033#M13862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See also:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/49078"&gt;Suspicious DNS Query ad nauseam&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 14:53:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19033#M13862</guid>
      <dc:creator>ECommand</dc:creator>
      <dc:date>2015-01-27T14:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19034#M13863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As per &lt;A href="https://live.paloaltonetworks.com/u1/19230"&gt;ECommand&lt;/A&gt;, this is brought up in the other thread.&amp;nbsp; There is a bug in the latest AV update that is causing DNS queries to be caught.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 15:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19034#M13863</guid>
      <dc:creator>Dz3015</dc:creator>
      <dc:date>2015-01-27T15:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19035#M13864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Haverstad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;There is a large number of changes made on the recent Antivirus database version, regarding DNS signature. Almost 80,000 new DNS signatures has been added to this database. Could you please let me know the AV version currently installed on your PAN firewall. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 16:35:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19035#M13864</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-01-27T16:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19036#M13865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting as today I enabled Spyware and Virus signatures on outbound DNS from our Domain Controllers and we're also seeing thousands of hits/matches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Domains such as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;d.audienceiq.com&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;d.p-td.com&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;p.adsymptotic.com&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class="p4" style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4" style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;They flag as Spyware so I assume it's the anti-spyware signatures catching them?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4" style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4" style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;Fair to say I switched off email notifications pretty quickly &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 17:34:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19036#M13865</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2015-01-27T17:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19037#M13866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Phew! Same here. I am going email crazy!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 20:45:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19037#M13866</guid>
      <dc:creator>dpayne</dc:creator>
      <dc:date>2015-01-27T20:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19038#M13867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - we have also seen this huge explosion in DNS alerts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have also noticed an odd aspect - the domain name in the Palo UI alert appears to be different to the email alerts generated by Palo e.g.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Panorama UI log entry shows &lt;STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;Suspicious DNS Query (generic:&lt;/SPAN&gt;bam.nr-data.net) - ID &lt;SPAN style="text-decoration: underline;"&gt;4091002&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;but the email generated from the event shows: &lt;SPAN style="font-family: 'Times New Roman','serif'; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-GB; mso-fareast-language: EN-GB; mso-bidi-language: AR-SA;"&gt;Suspicious DNS Query (generic:&lt;STRONG style="text-decoration: underline;"&gt;ozgghm.com&lt;/STRONG&gt;)(&lt;STRONG style="text-decoration: underline;"&gt;4091002&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman','serif'; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-GB; mso-fareast-language: EN-GB; mso-bidi-language: AR-SA;"&gt;so the same ID reference, but a different domain.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman','serif'; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-GB; mso-fareast-language: EN-GB; mso-bidi-language: AR-SA;"&gt;Rgds&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 20:48:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19038#M13867</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2015-01-27T20:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19039#M13868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am seeing this as well. Crazy!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 21:02:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19039#M13868</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2015-01-27T21:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19040#M13869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're running AV 1473-1947, daily automatic update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2015 07:02:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19040#M13869</guid>
      <dc:creator>pivvre</dc:creator>
      <dc:date>2015-01-28T07:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19041#M13870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After update to 1474-1949 things seems better.&lt;/P&gt;&lt;P&gt;It's now almost eerie quiet in my in-box&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2015 13:47:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/19041#M13870</guid>
      <dc:creator>Dulle</dc:creator>
      <dc:date>2015-01-28T13:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/71311#M40750</link>
      <description>&lt;P&gt;I'm seeing this same issue after a recent anti-virus update. Before I would only get maybe a few a day if that. Anyone else out there seeing this happen recently?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2016 03:39:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/71311#M40750</guid>
      <dc:creator>Moose</dc:creator>
      <dc:date>2016-01-21T03:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/71367#M40767</link>
      <description>&lt;P&gt;Same problem.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;gmx.net will not work, because&amp;nbsp;js.ui-portal.de will be detect as spyware. We have the problem with many content delivery Websites.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2016 15:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/71367#M40767</guid>
      <dc:creator>RogerBi</dc:creator>
      <dc:date>2016-01-21T15:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole explosion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/71368#M40768</link>
      <description>&lt;P&gt;Thanks for the response Roger. Looks like an update yesterday for A/V signatures. I scanned a handful of PC's and none of them came up infected. Looks like a ton of false positives. I'm calling PA now to see what the deal is.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2016 15:33:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sinkhole-explosion/m-p/71368#M40768</guid>
      <dc:creator>Moose</dc:creator>
      <dc:date>2016-01-21T15:33:27Z</dc:date>
    </item>
  </channel>
</rss>

