<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MALWARE-CNC DNS suspicious .bit dns query in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/malware-cnc-dns-suspicious-bit-dns-query/m-p/5163913#M1115245</link>
    <description>&lt;P&gt;Try&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show dns&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show run dns&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show fqdn&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not so sure you will get url request but try, then add this url to specific ACP and detect how try connect this url&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2024 15:32:04 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-08-21T15:32:04Z</dc:date>
    <item>
      <title>MALWARE-CNC DNS suspicious .bit dns query</title>
      <link>https://community.cisco.com/t5/network-security/malware-cnc-dns-suspicious-bit-dns-query/m-p/5163860#M1115241</link>
      <description>&lt;P&gt;I got alerts from my Firepower this morning for this. The source IP is my DNS server, and the destination was my DNS provider. I can't find anything in the alert that I can use to locate the system that actually issued the request to my DNS server. I'm guessing it was a website/domain being requested that triggered it, but how do I find out what that was. If I had that, I could then check my logs for which system requested it.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 13:55:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-cnc-dns-suspicious-bit-dns-query/m-p/5163860#M1115241</guid>
      <dc:creator>Scott.Ezell</dc:creator>
      <dc:date>2024-08-21T13:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: MALWARE-CNC DNS suspicious .bit dns query</title>
      <link>https://community.cisco.com/t5/network-security/malware-cnc-dns-suspicious-bit-dns-query/m-p/5163909#M1115244</link>
      <description>&lt;P&gt;You wouldn't see it based on the DNS query itself since that traffic was only between the internal and public DNS resolver from the firewall's perspective.&lt;/P&gt;
&lt;P&gt;However, you might be able to find the subsequent connection that would normally follow the end host having received an IP to match the FQDN. Search for that destination IP in your connection events (assuming you haven't rolled over the database records and you are logging all connections).&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 15:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-cnc-dns-suspicious-bit-dns-query/m-p/5163909#M1115244</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-08-21T15:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: MALWARE-CNC DNS suspicious .bit dns query</title>
      <link>https://community.cisco.com/t5/network-security/malware-cnc-dns-suspicious-bit-dns-query/m-p/5163913#M1115245</link>
      <description>&lt;P&gt;Try&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show dns&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show run dns&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show fqdn&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not so sure you will get url request but try, then add this url to specific ACP and detect how try connect this url&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 15:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-cnc-dns-suspicious-bit-dns-query/m-p/5163913#M1115245</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-21T15:32:04Z</dc:date>
    </item>
  </channel>
</rss>

