<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL categorization reasoning? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28502#M20826</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you go to www.virustotal.com you can look up a url and it will have a date saying when it was last scanned and its rating against AV clients. This does not give you the reasons for its categorization nor is it inline with PA's categorization but sometimes can be beneficial when trying to understand a timeline.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 May 2015 17:40:48 GMT</pubDate>
    <dc:creator>lewis</dc:creator>
    <dc:date>2015-05-04T17:40:48Z</dc:date>
    <item>
      <title>URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28497#M20821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Someone shared a link with me to a new startup company and I found it had been blocked and listed as malware by a PAN FW --&amp;nbsp; I am curious if there is a way to determine exactly what occurred that made that site categorized as malware -- and how I can lookup other URL's reason for categorization -- if available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2015 20:17:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28497#M20821</guid>
      <dc:creator>ajr0</dc:creator>
      <dc:date>2015-04-30T20:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28498#M20822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using Bright cloud or Pan db for URL categorization?&lt;/P&gt;&lt;P&gt;ou can manually verify the&amp;nbsp; category of any URL by entering it on the following web page: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.brightcloud.com/tools/url-ip-lookup.php"&gt;http://www.brightcloud.com/tools/url-ip-lookup.php&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://urlfiltering.paloaltonetworks.com/testasite.aspx"&gt;https://urlfiltering.paloaltonetworks.com/testasite.aspx &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not agree with the&amp;nbsp; categorization of an individual URL/website you can submit a recategorization request on this page:&lt;/P&gt;&lt;P&gt;&lt;A href="http://brightcloud.com/support/changerequest.php"&gt;&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://brightcloud.com/support/changerequest.php"&gt;http://brightcloud.com/support/changerequest.php&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also clear the Url cache using below command&lt;/P&gt;&lt;P&gt;&amp;gt;clear url-cache url www.xyz.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also please check the below document for your reference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2227"&gt;https://live.paloaltonetworks.com/docs/DOC-2227&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-regards&lt;/P&gt;&lt;P&gt;Rajiv&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2015 21:36:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28498#M20822</guid>
      <dc:creator>rsriramoju</dc:creator>
      <dc:date>2015-04-30T21:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28499#M20823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rajiv,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp; I am specifically looking for the reason why a URL was chosen to be categorized as malware -- for example xyz.com is malware because software hosted on site was found to be distributing malware for command and control or Cryptolocker...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2015 21:39:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28499#M20823</guid>
      <dc:creator>ajr0</dc:creator>
      <dc:date>2015-04-30T21:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28500#M20824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont think we can provide data on the classification history or how classification happens on the back-end. &lt;/P&gt;&lt;P&gt;If a&amp;nbsp; website was mis-categorized&amp;nbsp; and the best way to find out is look at what other vendors say about it.&lt;/P&gt;&lt;P&gt;You can go to www.virustotal.com and find out what vendors like Kaspersky. Fortinet , BitDefender etc say about the website.&lt;/P&gt;&lt;P&gt;If a majority of vendors classify the website as benign but PAN-DB does not , that means we mis-categorized it. At that point you could submit a request. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3625"&gt;How to Submit a Mis-Categorized URL for PAN-DB&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-regards&lt;/P&gt;&lt;P&gt;Rajiv&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2015 21:53:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28500#M20824</guid>
      <dc:creator>rsriramoju</dc:creator>
      <dc:date>2015-04-30T21:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28501#M20825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add some color to &lt;A href="https://live.paloaltonetworks.com/u1/33846"&gt;rsriramoju&lt;/A&gt;'s statement, we don't supply specific details most of the time because that is part of our detection algorithm.&lt;/P&gt;&lt;P&gt;Generally speaking, a domain is categorized as malware when there are malicious files hosted at the domain, a piece of malware makes calls to that domain, or similar actions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More times than not I've seen a malicious file hosted on a compromised server on the domain. It could be a legitimate domain, but due to some unpatched (or zero-day) vulnerability, a malicious actor has planted malware on a directory reachable publicly. Incidentally, it's also why reputation-based systems can fail to protect you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you own the domain and have a Palo Alto Networks support contract, you can open a support ticket to uncover more specifics.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Greg Wesson&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2015 22:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28501#M20825</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-04-30T22:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28502#M20826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you go to www.virustotal.com you can look up a url and it will have a date saying when it was last scanned and its rating against AV clients. This does not give you the reasons for its categorization nor is it inline with PA's categorization but sometimes can be beneficial when trying to understand a timeline.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 May 2015 17:40:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28502#M20826</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2015-05-04T17:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28503#M20827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, everything in virus total said it was clean --&amp;gt; www.neucoin.org.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however PAN marks as Malware -- I have personal no evidence supporting it being malware or clean which is why I wanted to see reasoning from PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there a way to follow up with PAN to determine reasoning?&amp;nbsp; I do not want to submit a re categorization because I do not know that it is clean.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 May 2015 16:17:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28503#M20827</guid>
      <dc:creator>ajr0</dc:creator>
      <dc:date>2015-05-05T16:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28504#M20828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am seeing it categorized as Stock Advice and Tools. Maybe they revisited this one for you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 May 2015 16:27:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28504#M20828</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2015-05-05T16:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28505#M20829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it must have just changed within past day or two as my logs in PA show it as Malware on 05-04-2015 at 11:37 est.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however, I'm still curious as to why it was listed as malware for a brief period of time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 May 2015 16:44:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28505#M20829</guid>
      <dc:creator>ajr0</dc:creator>
      <dc:date>2015-05-05T16:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: URL categorization reasoning?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28506#M20830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ajr13,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The web site could have been hosting malware (thus being categorized as malware).&amp;nbsp; If the site administrator was informed and then removed the malware and patched their server to prevent further malware being placed on the server.&amp;nbsp; The site then get a re-categorization request and since the malware is not there anymore it gets classified as it normally should be.&amp;nbsp; This is how I expect it works.&amp;nbsp; Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 May 2015 02:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-categorization-reasoning/m-p/28506#M20830</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2015-05-07T02:39:17Z</dc:date>
    </item>
  </channel>
</rss>

