<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Torpig Phone home DNS request in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/torpig-phone-home-dns-request/m-p/35949#M26421</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Been seeing lots of detection for this threat, but the attackers are external and are trying to reach our internal DNS servers.&amp;nbsp; We have checked those dns servers along with going over other traffic and AV consoles looking for bots/trojans.&amp;nbsp; Any ideas why I would be seeing the Torpig phone home dns request threat from outside attempting to reach internal dns servers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jul 2012 19:51:25 GMT</pubDate>
    <dc:creator>thandlon</dc:creator>
    <dc:date>2012-07-18T19:51:25Z</dc:date>
    <item>
      <title>Torpig Phone home DNS request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/torpig-phone-home-dns-request/m-p/35949#M26421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Been seeing lots of detection for this threat, but the attackers are external and are trying to reach our internal DNS servers.&amp;nbsp; We have checked those dns servers along with going over other traffic and AV consoles looking for bots/trojans.&amp;nbsp; Any ideas why I would be seeing the Torpig phone home dns request threat from outside attempting to reach internal dns servers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 19:51:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/torpig-phone-home-dns-request/m-p/35949#M26421</guid>
      <dc:creator>thandlon</dc:creator>
      <dc:date>2012-07-18T19:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Torpig Phone home DNS request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/torpig-phone-home-dns-request/m-p/35950#M26422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If outside means Internet then you will most likely see all sort of shit thats out there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems not uncommon that the noise level on the Internet (various bots and other junk) is 1-3kbit/s per ipaddress (based on own experience, might vary in your area &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your case if some internet ipaddresses tries to get to your DNS servers (which happends to have public ip's but security rules will block incoming requests from Internet) then you can use tcpdump through your internet router to verify the content of these packets and if you belive they are false positives then send it to the appid team?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 21:47:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/torpig-phone-home-dns-request/m-p/35950#M26422</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-18T21:47:59Z</dc:date>
    </item>
  </channel>
</rss>

