malware??

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

malware??

L2 Linker

Dumb question perhaps, but why is www.googletagservices.com/tag/js/gpt.js being flagged as a malicious URL?  It doesn't come up that way in PA's URL filtering site.

It's created a considerable jump in my botnet list.

Thanks in advance...

//moe

19 REPLIES 19

L7 Applicator

Hello VSU_ITSEC,

Recently, There was a BUG identified for the same and The fix has been shipped with current PAN-DB version.

Thanks

L7 Applicator

Hello VSU_ITSEC,

Could you please let us know what URL DB version running on your PAN firewall...?

Thanks

6.0.3

I hope 6.0.3 is the PAN OS version, but what is the URL DB version. You will get this information from GUI dashboard > General Information > URL Filtering version. OR from CLI > Show system Info  ---

Thanks

A good doc for your reference: How to Handle a URL Miscategorization

Thanks

L6 Presenter

Hi VSU_ITSEC,

I just did PAN-DB URL Lookup and its classified as Comp&Inter.

Best match  googletagservices.com
Categorycomputer-and-internet-info

Can you please provide me output for "test url googletagservices.com".

Regards,

Hardik Shah

googletagservices.com

  Search Engine


Any yes, that was my PAN- OS version #, my bad... URLfiltering is 2014.09.22.470

Hi VSU,

Firewall is doing correct catagorization, hence its not issue of mis-categorization.

admin@93-PA-VM-200> test url-info-cloud googletagservices.com

BM:

googletagservices.com,9,5,search-engines

www.googletagservices.com/tag/js/gpt.js,1,5,search-engines

www.googletagservices.com,1,5,computer-and-internet-info

Can you put enlarged URL/Threat log here. That will help us to understand issue in detail.

Regards,

Hardik Shah

Hi VSU,

Please find virustotal analysis, its not a malware.

https://www.virustotal.com/en/url/50ddccd826c769b904f0d115b89c71faaab91882ec50fbf76a791ee848c5c7d4/a...

Hence provide us threat/URL log to confirm potential false positive.

Regards,

Hardik Shah

from the CLI

@PA-5020-P(active)> test url www.googletagservices.com/tag/js/gpt.js

www.googletagservices.com/tag/js/gpt.js search-engines (Base db) expires in 0 seconds

www.googletagservices.com/tag/js/gpt.js search-engines (Cloud db)

i'll get the URL/threat log in a few...

misCats.jpg

Hello VSU_ITSEC,

It seems currently the PAN firewall is categorized properly. The above mentioned logs is for 09/22/14. As i said before, we had an issue with prior version and that has been fixed now. That is why, you don't have logs for current date ( 09/23/14-Block-URL).

Hope this helps.

Thanks

HI VSU,

Thanks for providing URL Logs, its confirmed now that its yesterdays log.I agree with HULK. Today classification looks good. Let us know if issue still appears.

Regards,

Hardik Shah

Have a new site in today's list with the same issue: g.symcd.com.  This is new for us (so is the device); how often does this happen?

Untitled3.jpgUntitled4.jpg

  • 5987 Views
  • 19 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!