<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2463#M1840</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19490"&gt;hshah&lt;/A&gt; -- &lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;BrightCloud's categorization is likely incorrect. We've observed the crazytall domains being used to serve ads, which is perfectly legitimate. However, we've also observed malware connecting out to these domains. Thus, we do not categorize the domains as malicious, because they aren't; but we do categorize them as suspicious, because, as &lt;A href="https://live.paloaltonetworks.com/u1/17985"&gt;Steven Puluka&lt;/A&gt; indicated, accessing them may indicate malware on the endpoint.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;That said, per Steven's submission to Test A Site, "Computer and Internet Info" probably isn't the best categorization. It's worth requesting a review of that, even if the optimal bucket isn't "Malware."&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Jul 2014 23:22:12 GMT</pubDate>
    <dc:creator>cblackmore</dc:creator>
    <dc:date>2014-07-16T23:22:12Z</dc:date>
    <item>
      <title>Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2458#M1835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone have a link to more information regarding this threat ID ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have searched PA's support site and the internet, and have had no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 21:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2458#M1835</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-07-16T21:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2459#M1836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Blonde.crazytall.com is a malware site, when a user/spyware tried to do DNS lookup firewall just blocked DNS. Which in turn subsequent conversation. Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14486" alt="Capture.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14486_Capture.PNG" style="height: 186px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer following document for more detail on log.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6443"&gt;How to Create a Custom Report for Suspicious DNS Queries&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 21:54:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2459#M1836</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-16T21:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2460#M1837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the quick response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, I do not fully understand your explanation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 22:00:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2460#M1837</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-07-16T22:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2461#M1838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19490"&gt;hshah&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Looks like there is an issue with the Test A Site database.&amp;nbsp; I just ran this on the PA research center and it shows clean as computer category.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="blondecrazytall.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14487_blondecrazytall.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/28351"&gt;craigmueller&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You should try to back trace the clients making the request for the site.&amp;nbsp; They are likely infected with malware.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 22:00:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2461#M1838</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-07-16T22:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2462#M1839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall has inbuilt mechanism to block DNS request for malicious web sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, lets say any user tries to access malicious website, which can damage network in future. In that case Firewall will block DNS query, so Connection will never be formed and Network is secure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Moreover administrator get a log, so he can talk to user about malicious access. If user is unaware of such access then his machine is compromised. Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/people/spuluka"&gt;steven&lt;/A&gt; Bright cloud detects it as malicious, may be we can submit request for PAN-DB to correct category.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 22:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2462#M1839</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-16T22:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2463#M1840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19490"&gt;hshah&lt;/A&gt; -- &lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;BrightCloud's categorization is likely incorrect. We've observed the crazytall domains being used to serve ads, which is perfectly legitimate. However, we've also observed malware connecting out to these domains. Thus, we do not categorize the domains as malicious, because they aren't; but we do categorize them as suspicious, because, as &lt;A href="https://live.paloaltonetworks.com/u1/17985"&gt;Steven Puluka&lt;/A&gt; indicated, accessing them may indicate malware on the endpoint.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;That said, per Steven's submission to Test A Site, "Computer and Internet Info" probably isn't the best categorization. It's worth requesting a review of that, even if the optimal bucket isn't "Malware."&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 23:22:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2463#M1840</guid>
      <dc:creator>cblackmore</dc:creator>
      <dc:date>2014-07-16T23:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2464#M1841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Cblackmore,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you think its a legitimate domain, than please submit a URL Category Change request to bright cloud. Follow bellow URL.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.brightcloud.com/tools/change-request-url-categorization.php" title="http://www.brightcloud.com/tools/change-request-url-categorization.php"&gt;URL Categorization Change Request | Webroot BrightCloud&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once Bright cloud updates URL, firewall will no longer thinks it a malware domain and allow this legitimate traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 23:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2464#M1841</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-16T23:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2465#M1842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Craigmueller,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Virustotal thinks it as a malicious website, hence most likely bright cloud will not change category. If virustotal think it as a malware, than there is something wrong with the website. Please follow bellow link.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/domain/blonde.crazytall.com/information/" style="font-size: 10pt; line-height: 1.5em;" title="https://www.virustotal.com/en/domain/blonde.crazytall.com/information/"&gt;https://www.virustotal.com/en/domain/blonde.crazytall.com/information/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jul 2014 23:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2465#M1842</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-16T23:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2466#M1843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19490"&gt;hshah&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL style="list-style-type: decimal;"&gt;&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/u1/28351"&gt;craigmueller&lt;/A&gt;'s original question was about a DNS signature, not URL Filtering functionality (whether BrightCloud or PAN-DB).&lt;/LI&gt;&lt;LI&gt;BrightCloud is not a factor in how we generate DNS signatures. Feel free to submit a change request to BrightCloud, but it will not affect our signatures.&lt;/LI&gt;&lt;LI&gt;VirusTotal does not believe blonde.crazytall.com to be malicious. VirusTotal is simply a data aggregator, and the data it has aggregated shows that &lt;A href="https://www.virustotal.com/en/url/108459681d95e87d245b6dd128bc30526e39866a3d8e632d1aa11ff2bff87bce/analysis/"&gt;of 57 URL scanners, none believe this domain to be malicious&lt;/A&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DNS signature exists for the reasons I stated earlier.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jul 2014 00:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2466#M1843</guid>
      <dc:creator>cblackmore</dc:creator>
      <dc:date>2014-07-17T00:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:blonde.crazytall.com)(4100529)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2467#M1844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think there is a categorization issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was really just interested in more information regarding this threat ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I am understanding everyone, this seems to be for pop-up ads or malware distribution?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is posted twice, I apologize. I previously responded, but no longer see it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jul 2014 16:32:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-blonde-crazytall-com-4100529/m-p/2467#M1844</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-07-17T16:32:01Z</dc:date>
    </item>
  </channel>
</rss>

