<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tons of &amp;quot;Generic:&amp;lt;URL&amp;gt; hits in threat logs for DNS Query hits in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tons-of-quot-generic-lt-url-gt-hits-in-threat-logs-for-dns-query/m-p/382366#M89841</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing a ton of "generic:&amp;lt;random-url&amp;gt;" hits in my threat logs under the spyware category for DNS queries from my email spam filter server out to the world. I have DNS security set up on the Palo so they are being sinkholed, but there are a ton of them, and several dozen different URL's.&amp;nbsp; The spam filter uses a proprietary software so it's unlikely it is infected. I suspect the queries are being made from the URL's being placed in the emails themselves. Wondering if anyone has seen this or can explain? These can't all be malicious URL's my users are referencing in their emails can they?&amp;nbsp; Here's a small example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dromanelli_0-1611763278220.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29688i1FD81E6817C9A09D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dromanelli_0-1611763278220.png" alt="dromanelli_0-1611763278220.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jan 2021 16:01:26 GMT</pubDate>
    <dc:creator>dromanelli</dc:creator>
    <dc:date>2021-01-27T16:01:26Z</dc:date>
    <item>
      <title>Tons of "Generic:&lt;URL&gt; hits in threat logs for DNS Query hits</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tons-of-quot-generic-lt-url-gt-hits-in-threat-logs-for-dns-query/m-p/382366#M89841</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing a ton of "generic:&amp;lt;random-url&amp;gt;" hits in my threat logs under the spyware category for DNS queries from my email spam filter server out to the world. I have DNS security set up on the Palo so they are being sinkholed, but there are a ton of them, and several dozen different URL's.&amp;nbsp; The spam filter uses a proprietary software so it's unlikely it is infected. I suspect the queries are being made from the URL's being placed in the emails themselves. Wondering if anyone has seen this or can explain? These can't all be malicious URL's my users are referencing in their emails can they?&amp;nbsp; Here's a small example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dromanelli_0-1611763278220.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29688i1FD81E6817C9A09D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dromanelli_0-1611763278220.png" alt="dromanelli_0-1611763278220.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 16:01:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tons-of-quot-generic-lt-url-gt-hits-in-threat-logs-for-dns-query/m-p/382366#M89841</guid>
      <dc:creator>dromanelli</dc:creator>
      <dc:date>2021-01-27T16:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Tons of "Generic:&lt;URL&gt; hits in threat logs for DNS Query hits</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tons-of-quot-generic-lt-url-gt-hits-in-threat-logs-for-dns-query/m-p/382635#M89870</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141381"&gt;@dromanelli&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I would expect this on an email security gateway to be honest. The number of DNS requests an email security gateway will make is dependent on mailflow, but they'll all generally resolve the source domain email was sent from, and a lot of them will resolve any domain that they see come across in a message. So all of the spam and phishing messages that you receive are likely going to be triggering alerts for all of those as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 16:55:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tons-of-quot-generic-lt-url-gt-hits-in-threat-logs-for-dns-query/m-p/382635#M89870</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-01-28T16:55:41Z</dc:date>
    </item>
  </channel>
</rss>

