<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain is pointed as Malware in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/domain-is-pointed-as-malware/m-p/941#M728</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Websites are categorized by Brightcloud if you have that subscription or by Palo if you are using Palo's. If this was a threat (shows up in the threat log), then it matches a signature defined as a threat/vulnerability. All (decent) firewall's use "signatures" or criteria that defines legit from illegitimate or questionable traffic. Most threats/vulnerabilities are already recognized/categorized by varying groups including the software makers themselves, and are submitted to the MITRE and is included in the NVD&amp;nbsp; called CVEs (Computer Vulnerabilities &amp;amp; Exposures). If I understand you correctly you saw the following threat: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H1 style="font-size: 2em; color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;DNS ANY Suspicious Query&lt;/H1&gt;&lt;H2 style="font-size: 1.2em; color: #000000; padding-bottom: 5px; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: #cccccc; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;Overview&lt;/H2&gt;&lt;TABLE style="border: 1px solid #aaaaaa; color: #252525; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;TBODY&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Attack Name&lt;/TD&gt;&lt;TD class="detail-field" style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;DNS ANY Suspicious Query&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Description&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;This alert indicates a suspicious specific DNS ANY reques.&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Threat ID&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;35184&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;References&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;&lt;A href="https://isc.sans.edu/diary.html?storyid=13261" style="color: #505abc; text-decoration: underline;" target="_blank"&gt;https://isc.sans.edu/diary.html?storyid=13261&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Severity&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;medium&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Category&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;info-leak&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Aug 2013 15:59:58 GMT</pubDate>
    <dc:creator>craymond</dc:creator>
    <dc:date>2013-08-05T15:59:58Z</dc:date>
    <item>
      <title>Domain is pointed as Malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/domain-is-pointed-as-malware/m-p/940#M727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;today we had a suspicious DNS Query&amp;nbsp; warning because we tried to reslove a domain (pandaro.be).&lt;/P&gt;&lt;P&gt;So Palo Alto gets information about domains and checks some information about these domeains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions about this:&lt;/P&gt;&lt;P&gt;1/ What is PA using&amp;nbsp; to decide which status a domain gets&lt;/P&gt;&lt;P&gt;2/ What is PA checking at a domain to decide about the status&lt;/P&gt;&lt;P&gt;2/ If a domain is known as Malware what has to be done to get it clean&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Greetings,&lt;/P&gt;&lt;P&gt;Rene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 15:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/domain-is-pointed-as-malware/m-p/940#M727</guid>
      <dc:creator>wolfrene</dc:creator>
      <dc:date>2013-08-05T15:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Domain is pointed as Malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/domain-is-pointed-as-malware/m-p/941#M728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Websites are categorized by Brightcloud if you have that subscription or by Palo if you are using Palo's. If this was a threat (shows up in the threat log), then it matches a signature defined as a threat/vulnerability. All (decent) firewall's use "signatures" or criteria that defines legit from illegitimate or questionable traffic. Most threats/vulnerabilities are already recognized/categorized by varying groups including the software makers themselves, and are submitted to the MITRE and is included in the NVD&amp;nbsp; called CVEs (Computer Vulnerabilities &amp;amp; Exposures). If I understand you correctly you saw the following threat: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H1 style="font-size: 2em; color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;DNS ANY Suspicious Query&lt;/H1&gt;&lt;H2 style="font-size: 1.2em; color: #000000; padding-bottom: 5px; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: #cccccc; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;Overview&lt;/H2&gt;&lt;TABLE style="border: 1px solid #aaaaaa; color: #252525; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;TBODY&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Attack Name&lt;/TD&gt;&lt;TD class="detail-field" style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;DNS ANY Suspicious Query&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Description&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;This alert indicates a suspicious specific DNS ANY reques.&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Threat ID&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;35184&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;References&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;&lt;A href="https://isc.sans.edu/diary.html?storyid=13261" style="color: #505abc; text-decoration: underline;" target="_blank"&gt;https://isc.sans.edu/diary.html?storyid=13261&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Severity&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;medium&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Category&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;info-leak&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 15:59:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/domain-is-pointed-as-malware/m-p/941#M728</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-08-05T15:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Domain is pointed as Malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/domain-is-pointed-as-malware/m-p/942#M729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Wolfrene,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA is using a combination of the category of the URL, Known CVE IDs that may be associated with a domain.&lt;/P&gt;&lt;P&gt;The Palo Alto content team constantly keeps monitoring and reevaluating the malicious or benign nature of such URLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best way to get a domain clean that has been categorized as Malware is to have a TAC case opened up with pcaps of the threat traffic ( this can be done by enabling pcap on the threat profile that triggered this threat log), screen shot of the threat log and the tech support file.&lt;/P&gt;&lt;P&gt;The TAC will have this domain re-evaluated by the Content team and if changes are made to this threat signature then push the change with the next content release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 16:43:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/domain-is-pointed-as-malware/m-p/942#M729</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-08-05T16:43:05Z</dc:date>
    </item>
  </channel>
</rss>

