<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: issue with 	malwaredomainlist.ip in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-malwaredomainlist-ip/m-p/76649#M99571</link>
    <description>&lt;P&gt;I am also working on a tracing function, to let the admin trace the flow of indicators across the graph. Should happen in a week or two.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Apr 2016 08:29:03 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2016-04-19T08:29:03Z</dc:date>
    <item>
      <title>issue with 	malwaredomainlist.ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-malwaredomainlist-ip/m-p/76600#M99569</link>
      <description>&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added the "malwaredomainlist.ip" as miner.&lt;/P&gt;&lt;P&gt;This is working (shows that it has mined about 1500 IPs), but when I add the miner input to a ipv4 or domain aggregator I do not get any output...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-04-18 16_09_21-minemeld.png" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3590iC26F53B919AF079B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2016-04-18 16_09_21-minemeld.png" alt="2016-04-18 16_09_21-minemeld.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 14:09:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-malwaredomainlist-ip/m-p/76600#M99569</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2016-04-18T14:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: issue with 	malwaredomainlist.ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-malwaredomainlist-ip/m-p/76611#M99570</link>
      <description>&lt;P&gt;Dear mr.linus,&lt;/P&gt;
&lt;P&gt;malwaredomainlist.ip generates IPv4 addresses only, that's the reason domain aggregator does not accept any of the generated indicators. If you check the prototype for stdlib.aggregatorDomain you will see the inbound filters applied to all the indicators. These filters accept WITHDRAWS and indicators with type domain. Evertyhing else is dropped.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2016-04-18 at 16.51.26.png" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3595i361E6196D39C3BBB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2016-04-18 at 16.51.26.png" alt="Screen Shot 2016-04-18 at 16.51.26.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The IPv4 aggregator instead should accept, but again it depends on the prototype you used to create the aggregator. malwaredomainlist.ip provides C2 IPs, and the indictors are marked as "outbound". Please, could you check that the IPv4 aggregator accepts "outbound" indicators ? You can look at the inbound filters inside the prototype.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would be a good idea&amp;nbsp;to add a new miner to poll the CSV file provided by malwaredomainlist instead of the IP list. I have created an ER (#8) to track this.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 14:59:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-malwaredomainlist-ip/m-p/76611#M99570</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-04-18T14:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: issue with 	malwaredomainlist.ip</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-malwaredomainlist-ip/m-p/76649#M99571</link>
      <description>&lt;P&gt;I am also working on a tracing function, to let the admin trace the flow of indicators across the graph. Should happen in a week or two.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 08:29:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-malwaredomainlist-ip/m-p/76649#M99571</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-04-19T08:29:03Z</dc:date>
    </item>
  </channel>
</rss>

