<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: malware?? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12312#M9015</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi VSU,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find virustotal analysis, its not a malware.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/url/50ddccd826c769b904f0d115b89c71faaab91882ec50fbf76a791ee848c5c7d4/analysis/1411493884/" style="font-size: 10pt; line-height: 1.5em;" title="https://www.virustotal.com/en/url/50ddccd826c769b904f0d115b89c71faaab91882ec50fbf76a791ee848c5c7d4/analysis/1411493884/"&gt;https://www.virustotal.com/en/url/50ddccd826c769b904f0d115b89c71faaab91882ec50fbf76a791ee848c5c7d4/analysis/1411493884/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence provide us threat/URL log to confirm potential false positive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Sep 2014 17:39:38 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-09-23T17:39:38Z</dc:date>
    <item>
      <title>malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12303#M9006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dumb question perhaps, but why is www.googletagservices.com/tag/js/gpt.js being flagged as a malicious URL?&amp;nbsp; It doesn't come up that way in PA's URL filtering site.&lt;/P&gt;&lt;P&gt;It's created a considerable jump in my botnet list.&lt;/P&gt;&lt;P&gt;Thanks in advance...&lt;/P&gt;&lt;P&gt;//moe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 14:58:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12303#M9006</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-09-23T14:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12304#M9007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello VSU_ITSEC,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recently, There was a BUG identified for the same and The fix has been shipped with current PAN-DB version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 15:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12304#M9007</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-23T15:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12305#M9008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1939" data-externalid="" data-presence="null" data-userid="26529" data-username="VSU_ITSEC" href="https://live.paloaltonetworks.com/people/VSU_ITSEC" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;VSU_ITSEC&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please let us know what URL DB version running on your PAN firewall...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 15:07:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12305#M9008</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-23T15:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12306#M9009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;6.0.3&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 15:20:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12306#M9009</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-09-23T15:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12307#M9010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope 6.0.3 is the PAN OS version, but what is the URL DB version. You will get this information from GUI dashboard &amp;gt; General Information &amp;gt; &lt;SPAN style="color: #798993; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 11px; text-align: right; background-color: #fbfcfc;"&gt;URL Filtering version. OR from CLI &amp;gt; Show system Info&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&amp;nbsp; ---&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 15:28:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12307#M9010</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-23T15:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12308#M9011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A good doc for your reference: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-2227"&gt;How to Handle a URL Miscategorization&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 15:30:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12308#M9011</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-23T15:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12309#M9012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi VSU_ITSEC,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just did PAN-DB URL Lookup and its classified as Comp&amp;amp;Inter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE style="border: 1px outset gray; font-family: 'Times New Roman'; background-color: white;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: 1px inset gray; padding: 1px;"&gt;Best match&amp;nbsp; &lt;/TD&gt;&lt;TD style="border: 1px inset gray; padding: 1px;"&gt;googletagservices.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border: 1px inset gray; padding: 1px;"&gt;Category&lt;/TD&gt;&lt;TD style="border: 1px inset gray; padding: 1px;"&gt;computer-and-internet-info&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please provide me output for "test url googletagservices.com".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 17:00:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12309#M9012</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-23T17:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12310#M9013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;LABEL for="URL"&gt;URL&lt;/LABEL&gt;&lt;/P&gt;&lt;P class="editor-field"&gt;googletagservices.com &lt;/P&gt;&lt;P class="editor-label"&gt;&lt;LABEL for="CategoryName"&gt;Category&lt;/LABEL&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;STRONG&gt;Search Engine&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any yes, that was my PAN- OS version #, my bad... URLfiltering is 2014.09.22.470&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 17:19:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12310#M9013</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-09-23T17:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12311#M9014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi VSU,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall is doing correct catagorization, hence its not issue of mis-categorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@93-PA-VM-200&amp;gt; test url-info-cloud googletagservices.com&lt;/P&gt;&lt;P&gt;BM:&lt;/P&gt;&lt;P&gt;googletagservices.com,9,5,search-engines&lt;/P&gt;&lt;P&gt;www.googletagservices.com/tag/js/gpt.js,1,5,search-engines&lt;/P&gt;&lt;P&gt;www.googletagservices.com,1,5,computer-and-internet-info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you put enlarged URL/Threat log here. That will help us to understand issue in detail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 17:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12311#M9014</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-23T17:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12312#M9015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi VSU,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find virustotal analysis, its not a malware.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/url/50ddccd826c769b904f0d115b89c71faaab91882ec50fbf76a791ee848c5c7d4/analysis/1411493884/" style="font-size: 10pt; line-height: 1.5em;" title="https://www.virustotal.com/en/url/50ddccd826c769b904f0d115b89c71faaab91882ec50fbf76a791ee848c5c7d4/analysis/1411493884/"&gt;https://www.virustotal.com/en/url/50ddccd826c769b904f0d115b89c71faaab91882ec50fbf76a791ee848c5c7d4/analysis/1411493884/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence provide us threat/URL log to confirm potential false positive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 17:39:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12312#M9015</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-23T17:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12313#M9016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from the CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@PA-5020-P(active)&amp;gt; test url www.googletagservices.com/tag/js/gpt.js&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;www.googletagservices.com/tag/js/gpt.js search-engines (Base db) expires in 0 seconds&lt;/P&gt;&lt;P&gt;www.googletagservices.com/tag/js/gpt.js search-engines (Cloud db)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'll get the URL/threat log in a few...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 17:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12313#M9016</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-09-23T17:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12314#M9017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="misCats.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15696_misCats.jpg" style="height: 362px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 17:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12314#M9017</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-09-23T17:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12315#M9018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1939" data-externalid="" data-presence="null" data-userid="26529" data-username="VSU_ITSEC" href="https://live.paloaltonetworks.com/people/VSU_ITSEC" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;VSU_ITSEC&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems currently the PAN firewall is categorized properly. The above mentioned logs is for 09/22/14. As &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt; said before, we had an issue with prior version and that has been fixed now. That is why, you don't have logs for &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;current date&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;09/23/14-Block-URL).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 17:58:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12315#M9018</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-23T17:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12316#M9019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI VSU,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for providing URL Logs, its confirmed now that its yesterdays log.&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I agree with HULK. Today classification looks good. Let us know if issue still appears.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 18:23:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12316#M9019</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-23T18:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12317#M9020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have a new site in today's list with the same issue: g.symcd.com.&amp;nbsp; This is new for us (so is the device); how often does this happen?&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15796" alt="Untitled3.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15796_Untitled3.jpg" style="height: 198px; width: 620px;" /&gt;&lt;IMG alt="Untitled4.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15799_Untitled4.jpg" style="height: 114px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 15:27:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12317#M9020</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-09-25T15:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12318#M9021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What output you are getting for this new URL from "&amp;gt;test url " command&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; .&lt;/SPAN&gt;.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 15:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12318#M9021</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-25T15:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12319#M9022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For us its comp&amp;amp;Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@85-PA-VM-300&amp;gt; test url-info-cloud g.symcd.com&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;BM:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;symcd.com,9,5,computer-and-internet-info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please provide us output for &lt;/P&gt;&lt;P&gt;test url-info-cloud g.symcd.com&lt;/P&gt;&lt;P&gt;show system info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 17:20:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12319#M9022</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-25T17:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12320#M9023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;@PA-5020-P(active)&amp;gt; test url g.symcd.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;g.symcd.com computer-and-internet-info (Base db) expires in 0 seconds&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;g.symcd.com computer-and-internet-info (Cloud db)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;I see where you are going w/this….&amp;nbsp; So…&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;Am I to verify each entry on my botnet report prior to taking action?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;Am I getting URL updates soon enough, an if not, where do I adjust?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;Am I placing too much ‘faith’ in the botnet report?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;From the botnet report:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;confidence&amp;nbsp;&amp;nbsp;&amp;nbsp; Virtual System&amp;nbsp;&amp;nbsp;&amp;nbsp; description&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (42) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (441) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (65) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (59) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCK7KMAoI08AAGfwI84AAACi&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (40) the same malicious URL acuityplatform.com/Adserver/exds?xuid=8f02281c60d856473aab5158f5ac729c&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (123) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (190) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (63) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCLtJMAoI0gAAHjWIP0AAABR&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (68) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (65) the same malicious URL acuityplatform.com/Adserver/exds?xuid=ef8c5c814844f7f359896d10d97045dd&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (100) the same malicious URL cache.dtmpub.com/js/ncg6/0/optinrt_0.js?cgver=36931&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (51) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCLVhsAoI0YAACmlXH8AAACE&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (198) the same malicious URL g.symcd.com/MEkwR6ADAgEAMEAwPjA8MAkGBSsOAwIaBQAEFLG0OReQFreXeVAR8WC51KI82+3uBBQA+SrDQZG2ycK4PlXywJcRE6AHIAIDAjp2&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (39) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCLTtsAoIz0AAAZPA.MAAACV&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (45) the same malicious URL cache.dtmpub.com/js/ncg6/0/optinrt_0.js?cgver=36931&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (73) the same malicious URL acuityplatform.com/Adserver/atds?getuserid=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://ums.adtechus.com/mapuser?providerid=1027;userid=$UID" rel="nofollow"&gt;http://ums.adtechus.com/mapuser?providerid=1027;userid=$UID&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (157) the same malicious URL acuityplatform.com/Adserver/atds?getuserid=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://ums.adtechus.com/mapuser?providerid=1027;userid=$UID" rel="nofollow"&gt;http://ums.adtechus.com/mapuser?providerid=1027;userid=$UID&lt;/A&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (47) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCLeicAoI0YAAD4Vd2cAAAAD&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (121) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCMOwMAoI0oAAEKePowAAADV&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (45) the same malicious URL acuityplatform.com/Adserver/atds?getuserid=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://ums.adtechus.com/mapuser?providerid=1027;userid=$UID" rel="nofollow"&gt;http://ums.adtechus.com/mapuser?providerid=1027;userid=$UID&lt;/A&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (36) the same malicious URL assets.tumblr.com/fonts/gibson/stylesheet.css?v=3&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (575) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (43) the same malicious URL acuityplatform.com/Adserver/exds?xuid=41ed950b4ac8a2da0effdb75f6b13fe2&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (45) the same malicious URL cache.dtmpub.com/js/ncg6/0/optinrt_0.js?cgver=36953&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (127) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCLQicAoIzcAAIBXHTwAAAD7&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (133) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (107) the same malicious URL cache.dtmpub.com/js/ncg6/0/optinrt_0.js?cgver=36939&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (38) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCLi5cAoI0oAAJ2eaAIAAAAD&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (150) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (38) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCLwVMAoIzsAABrw-C0AAAE8&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (42) the same malicious URL cdn.mxpnl.com/libs/mixpanel-2.2.min.js&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (187) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (58) the same malicious URL acuityplatform.com/Adserver/cmds?cm_dsp_id=10&amp;amp;cm_callback_url=http:/dsum.casalemedia.com/rum&amp;amp;cm_user_id=VCL9o8AoIzMAABBzJg0AAABO&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (51) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (85) the same malicious URL g.symcd.com/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (54) the same malicious URL g.symcd.com/MEkwR6ADAgEAMEAwPjA8MAkGBSsOAwIaBQAEFLG0OReQFreXeVAR8WC51KI82+3uBBQA+SrDQZG2ycK4PlXywJcRE6AHIAIDAjp2&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (163) the same malicious URL acuityplatform.com/Adserver/atds?getuserid=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://ums.adtechus.com/mapuser?providerid=1027;userid=$UID" rel="nofollow"&gt;http://ums.adtechus.com/mapuser?providerid=1027;userid=$UID&lt;/A&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (70) the same malicious URL ortc-ws6-useast1-s0003.realtime.co/&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; Repeatedly visited (555) the same malicious URL g.symcd.com/MEkwR6ADAgEAMEAwPjA8MAkGBSsOAwIaBQAEFLG0OReQFreXeVAR8WC51KI82+3uBBQA+SrDQZG2ycK4PlXywJcRE6AHIAIDAjp2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 21:38:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12320#M9023</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-09-25T21:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12321#M9024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm seeing the same behaviour in our botnet report. Mulitiple users repeatedly visiting supposedly malicious URLs. All URLs seem to be related to advertisement or cnd. Running pan-db 2014.09.25.451.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a open case with TAC&amp;nbsp; regarding this. Will let you know how it goes. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 08:05:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12321#M9024</guid>
      <dc:creator>torm</dc:creator>
      <dc:date>2014-09-26T08:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: malware??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12322#M9025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi VSU,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just resolved one similar issue. follow bellow steps.&lt;/P&gt;&lt;P&gt;1. Download latest PAN-DB&lt;/P&gt;&lt;P&gt;2. Clear ur-cache &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;googletagservices.com/tag/js/gpt.js&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3. Now access, it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;HArdik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 17:48:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malware/m-p/12322#M9025</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-26T17:48:23Z</dc:date>
    </item>
  </channel>
</rss>

