<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic URL classified as Malware but not sinkholed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-classified-as-malware-but-not-sinkholed/m-p/207656#M60841</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quick question for a specific URL (cia.toh.info)&amp;nbsp; This URL is classified as malware in PAN-DB but doesn't show ip in the AV release notes as a malware site so it doesn't get sinkholed when we do a DNS lookup for that url.&amp;nbsp; We've noticed other URLs exhibiting the same behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else seen this?&amp;nbsp; Is there a disconnect between the PAN-DB classification and the AV (sinkhole) database?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Mar 2018 13:02:44 GMT</pubDate>
    <dc:creator>epeeler</dc:creator>
    <dc:date>2018-03-27T13:02:44Z</dc:date>
    <item>
      <title>URL classified as Malware but not sinkholed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-classified-as-malware-but-not-sinkholed/m-p/207656#M60841</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quick question for a specific URL (cia.toh.info)&amp;nbsp; This URL is classified as malware in PAN-DB but doesn't show ip in the AV release notes as a malware site so it doesn't get sinkholed when we do a DNS lookup for that url.&amp;nbsp; We've noticed other URLs exhibiting the same behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else seen this?&amp;nbsp; Is there a disconnect between the PAN-DB classification and the AV (sinkhole) database?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 13:02:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-classified-as-malware-but-not-sinkholed/m-p/207656#M60841</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2018-03-27T13:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: URL classified as Malware but not sinkholed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-classified-as-malware-but-not-sinkholed/m-p/207670#M60843</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8533"&gt;@epeeler&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These two sources aren't in sync completely. This domain was sinkholed with a WF update from 20160505. Some time after that the domain was removed from the dns signatures. This needs to be done over time, when it is "safe" to remove it. The list of dns signatures would simply be too big for the firewalls to handle if it would contain ALL malware domains from PAN-DB. For the dns signatures there is no cloud lookup like with PAN-DB.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;: Do you agree?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 13:33:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-classified-as-malware-but-not-sinkholed/m-p/207670#M60843</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-27T13:33:54Z</dc:date>
    </item>
  </channel>
</rss>

