<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nexus-websocket-a.intercom.io in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4738907#M1095959</link>
    <description>&lt;P&gt;Same here. Trying to track down correlation to the origination of the traffic.&amp;nbsp; It appears, at least in our situation, that it is an embedded application in Microsoft Teams or other MS applications.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2022 15:52:21 GMT</pubDate>
    <dc:creator>tkamish22</dc:creator>
    <dc:date>2022-12-14T15:52:21Z</dc:date>
    <item>
      <title>nexus-websocket-a.intercom.io</title>
      <link>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4738646#M1095946</link>
      <description>&lt;P&gt;We've been receiving multiple alert regarding this domain "&lt;SPAN&gt;nexus-websocket-a.intercom.io"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;User traffic shows it's related to legitimate web traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Submitted the domain to sandboxing and it's benign. Also other OSINT categorized it under Technology/Internet and Business-and-Economy.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Checked Cisco Talos portal and this has been categorized as phishing recently, Dec.12.&lt;/P&gt;&lt;P&gt;Requested re-categorization on this via Cisco Talos and it's still pending.&lt;/P&gt;&lt;P&gt;Would like to know your thoughts or if anyone has encountered this domain? Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 10:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4738646#M1095946</guid>
      <dc:creator>justwondering</dc:creator>
      <dc:date>2022-12-14T10:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: nexus-websocket-a.intercom.io</title>
      <link>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4738792#M1095947</link>
      <description>&lt;P&gt;I too have observed this recently. It seems some sources note it as malicious, while others do not. I'm curious as well as I do not have a definite answer. Resource monitor on Windows machines shows chrome.exe as the culprit... but as for what it is... no idea.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 19:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4738792#M1095947</guid>
      <dc:creator>brettp</dc:creator>
      <dc:date>2022-12-14T19:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: nexus-websocket-a.intercom.io</title>
      <link>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4738907#M1095959</link>
      <description>&lt;P&gt;Same here. Trying to track down correlation to the origination of the traffic.&amp;nbsp; It appears, at least in our situation, that it is an embedded application in Microsoft Teams or other MS applications.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 15:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4738907#M1095959</guid>
      <dc:creator>tkamish22</dc:creator>
      <dc:date>2022-12-14T15:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: nexus-websocket-a.intercom.io</title>
      <link>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4739746#M1095993</link>
      <description>&lt;P&gt;same on my end, it's initiating process is chrome.exe or edge.exe&amp;nbsp;&lt;/P&gt;&lt;P&gt;checked logs further and seeing the domain ctaegorization is different in between cisco umbrella and firepower.. aren't they suppose to have threat intelligence?&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower has urlfiltering, nonetheless its DNS Category=Phishing, while umbrella assessed it under&amp;nbsp;Software/Technology, Business Services, Application, Business and Industry.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 15:01:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4739746#M1095993</guid>
      <dc:creator>justwondering</dc:creator>
      <dc:date>2022-12-15T15:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: nexus-websocket-a.intercom.io</title>
      <link>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4740981#M1096037</link>
      <description>&lt;P&gt;Updating this, Cisco Talos has fixed the categorization to TRUSTED&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;** Fixed - FP - Talos has concluded that the submission is safe to access at this time; the submission's reputation has been improved&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Dec 2022 09:02:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nexus-websocket-a-intercom-io/m-p/4740981#M1096037</guid>
      <dc:creator>justwondering</dc:creator>
      <dc:date>2022-12-17T09:02:44Z</dc:date>
    </item>
  </channel>
</rss>

