update.newinfoclientstack.com

Reply
Highlighted
L4 Transporter

update.newinfoclientstack.com

I looked in the threat database and PA classifies this URL Inbox  update.newinfoclientstack.com as maleware. Is there a way to know if this is covered by the threat prevention subscription? There were no details in how to deal with it in the database

 
Highlighted
Cyber Elite

@jdprovine,

The newinfoclientstack.com domain is only listed as malware because of the listing in PAN-DB URL Classifications and therefore isn't covered with the threat prevention subscription. The only thing that the threat prevention license is going to cover is antivirus, anti-spyware, and vulnerability proctection updates. 

Keep in mind that you still have access to URL filtering by the devices Base db; in this case it doesn't do you much good as the Base db is listing it as a content-delivery-network while the Cloud db is listing it as Malware. 

Highlighted
L4 Transporter

@BPry

This is the URL that was requested to be blocked, but i see no evidence it has ever tried on the firewall. Just trying to figure out the best way to deal with these issues and not make excessive work

Highlighted
Cyber Elite

@jdprovine,

Do you have an active 'blacklist' so to speak? You could build an EBL that was only for addresses that were going to be blocked and then put any such request like this in that 'blacklist' policy. If you utilize MineMeld you could even build in an age-out limit so that entries are automatically removed after x amount of time. That's how I deal with requests such as this. 

Highlighted
L4 Transporter

@BPry

We were able to add it to our exisiting MISP list so we are good to go, But it is good to know that I could create a a seperate rule and profile 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!