<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspicious DNS Query (generic:contador.hotelarena.top) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-contador-hotelarena-top/m-p/365793#M88601</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163372"&gt;@Alisson-Jsl&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recommend that you enable packet capture on the alert for further analysis.&amp;nbsp; If you suspect a false positive then please collect the PCAP and reach out to support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 26 Nov 2020 13:43:52 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2020-11-26T13:43:52Z</dc:date>
    <item>
      <title>Suspicious DNS Query (generic:contador.hotelarena.top)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-contador-hotelarena-top/m-p/364977#M88524</link>
      <description>&lt;P&gt;Boa tarde pessoal,&amp;nbsp;&lt;/P&gt;&lt;P&gt;estou com comportamento estranho em meu Firewall.&lt;/P&gt;&lt;P&gt;notamos muitas requisições do meu servidor de dns interno para o dns externo com " type spyware "&amp;nbsp;&lt;/P&gt;&lt;P&gt;Verifiquem o anexo.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Suspicious DNS Query.PNG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28776iC3B33971CB388F03/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Suspicious DNS Query.PNG" alt="Suspicious DNS Query.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 19:48:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-contador-hotelarena-top/m-p/364977#M88524</guid>
      <dc:creator>Alisson-Jsl</dc:creator>
      <dc:date>2020-11-23T19:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query (generic:contador.hotelarena.top)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-contador-hotelarena-top/m-p/365793#M88601</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163372"&gt;@Alisson-Jsl&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recommend that you enable packet capture on the alert for further analysis.&amp;nbsp; If you suspect a false positive then please collect the PCAP and reach out to support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 26 Nov 2020 13:43:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-generic-contador-hotelarena-top/m-p/365793#M88601</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-11-26T13:43:52Z</dc:date>
    </item>
  </channel>
</rss>

