Since midday yesterday (Monday Jan 26th) we've seen an explosion in sinkhole detections.
Previous moths sees one ot two a day in average, latest 24 hrs we've had more than 16.000 detections. This started after the antivirusupdate on Monday.
When checking a few of the domains via on-line URL-checking tools, no suspicious content is detected.
Latest antivirus signature contained a lot of Suspicious DNS adresses, but none of 'ours'
Has anyone else seen this ?
All DNS requests are blocked so no dangerous situation appears, but we suspect most of these requests to be false positive.
Can someone at PaloAlto check on this please?
There is a large number of changes made on the recent Antivirus database version, regarding DNS signature. Almost 80,000 new DNS signatures has been added to this database. Could you please let me know the AV version currently installed on your PAN firewall.
Interesting as today I enabled Spyware and Virus signatures on outbound DNS from our Domain Controllers and we're also seeing thousands of hits/matches.
Domains such as:
They flag as Spyware so I assume it's the anti-spyware signatures catching them?
Fair to say I switched off email notifications pretty quickly :smileyhappy:
Hi - we have also seen this huge explosion in DNS alerts.
We have also noticed an odd aspect - the domain name in the Palo UI alert appears to be different to the email alerts generated by Palo e.g.
so the same ID reference, but a different domain.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The Live Community thanks you for your participation!