dnsproxy failures

cancel
Showing results for 
Search instead for 
Did you mean: 

dnsproxy failures

L1 Bithead

System log fills with messages like "Failed to resolve domain name:defrxpwgklm.capco.com after trying all attempts to name server(s): 8.8.4.4  194.25.0.68". DNS without dnsproxy is working. Can i restart the dnsproxy to fix this issue?

The messages are appearing after some threats of type "Suspicious DNS Query".

3 REPLIES 3

L6 Presenter

Which version Panos you use ?

you use dns proxy on PaloAlto ? you tried to restart ,did it solve ?

I wouldnt be suprised if defrxpwgklm.capco.com is a malware url, I have seen similar design of the subdomain part which previously have been classified as malware-related.

Also currently it doesnt seem to resolve at all:

;; QUESTION SECTION:

;defrxpwgklm.capco.com.         IN      ANY

;; AUTHORITY SECTION:

capco.com.              3600    IN      SOA     ns1.netnames.net. hostmaster.net

names.net. 2013032800 10800 1800 3600000 21600

L4 Transporter

Old thread, but as it is still visible - from description it seems to be matching scenario described in following KB article:

https://live.paloaltonetworks.com/t5/Management-Articles/Blocking-Suspicious-DNS-Queries-with-DNS-Pr...

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!