Legit Suspicious DNS Query?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Legit Suspicious DNS Query?

L2 Linker

Since 2013/12/26 I have been seeing a large number of Suspicious DNS Queries (generic: xml12es.farolatino.com), threatid 4011926.  After researching the computers that are getting this, they all seem to be going to Microsoft sites prior to this query.  From what I have read this seams to be coming from Microsoft Media Player.  They use this site for their online media catalog.  Has anyone else seen this?

1 ACCEPTED SOLUTION

Accepted Solutions

L5 Sessionator

Hello Randy Greenspon,

This is a false positive. The signature is now disabled and the fix will be available in AV-1186.

Hope that helps!

Thanks and regards,

Kunal Adak

View solution in original post

7 REPLIES 7

L5 Sessionator

Hello Randy Greenspon,

This is a false positive. The signature is now disabled and the fix will be available in AV-1186.

Hope that helps!

Thanks and regards,

Kunal Adak

Thanks for confirming this and I have seen it get removed in AV-1186.  However with the addition of AV-1187  we are now getting another, I believe false positive of ThreatID 4034267, generic:msreg.gale.com

Hello rgreens,

msreg.gale.com domain is not a false positive. "Wildfire has detected a malware sample (ba491bb1eb3d62c5520883c8a24ac08f) which tried to resolve this domain "msreg.gale.com", which can not be resolved. So a malware sample tried to visit an un-resolvable domain and hence we marked this domain as malware"

Hope that helps!

Thanks and regards,

Kunal Adak

L4 Transporter

Hello rgreens


I also have this problem, DNS queries:


  • msreg.gale.com
  • lb-1.ezakus.net
  • track.yeshj.com
  • api28.thetrafficstat.net
  • pix.trafficjoint.com
  • file.soft365.com
  • ...
  • ..

How to fix it?

Thank you,


Diego

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!