<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks for the response. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075518#M17703</link>
    <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;
&lt;P&gt;There were successful connections before blocking this domain in proxy but we still see proxy and ips log towards the "counter.yadro.ru".&lt;/P&gt;
&lt;P&gt;If possible, can you share us much more info regarding the same. Need to troubleshoot the system from which we use logs for this domain.&lt;/P&gt;
&lt;P&gt;The suspected part is eventhough there is no redirection observed proxy ips logs towards this domain.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Ramahandran&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jun 2017 20:58:57 GMT</pubDate>
    <dc:creator>ramachandran.gunasekaran</dc:creator>
    <dc:date>2017-06-19T20:58:57Z</dc:date>
    <item>
      <title>BLACKLIST DNS request for known malware domain counter.yadro.ru</title>
      <link>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075516#M17701</link>
      <description>&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;alert udp $HOME_NET any -&amp;gt; any 53 (msg:"BLACKLIST DNS request for known malware domain counter.yadro.ru"; flow:to_server; byte_test:1,!&amp;amp;,0xF8,2; content:"|07|counter|05|yadro|02|ru|00|"; fast_pattern:only; metadata:impact_flag red, service dns; reference:url,www.virustotal.com/en/domain/counter.yadro.ru/information/; classtype:trojan-activity; sid:29119; rev:1; )&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Hi Team,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;For the above rule, we observed numerous connection due to the redirection. we have blocked the domain in proxy. but we also thinking to block the same in IPS since the reputation of the domain is high malicious.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;reference:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; background: white; vertical-align: baseline;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&lt;A href="https://virustotal.com/en/domain/yadro.ru/information/"&gt;https://virustotal.com/en/domain/yadro.ru/information/&lt;/A&gt;&lt;P&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; background: white; vertical-align: baseline;"&gt;&lt;U&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&lt;A href="https://www.hybrid-analysis.com/sample/aeb26c5c1caae1ddd9ea63266080e27d29ced1a48090c5be3e77aef3e2534b47?environmentId=1"&gt;https://www.hybrid-analysis.com/sample/aeb26c5c1caae1ddd9ea63266080e27d29ced1a48090c5be3e77aef3e2534b47?environmentId=1&lt;/A&gt;&lt;P&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-bottom: .0001pt; line-height: 15.0pt; background: white; vertical-align: baseline;"&gt;&lt;A href="https://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning/what-is-counter-yadro/3b7a3384-6eba-4225-ac6f-54f58e837bdd"&gt;&lt;SPAN style="color: windowtext;"&gt;https://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning/what-is-counter-yadro/3b7a3384-6eba-4225-ac6f-54f58e837bdd&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;A href="http://www.precisesecurity.com/hijacker/get-rid-counter-yadro-ru"&gt;&lt;SPAN style="color: windowtext;"&gt;http://www.precisesecurity.com/hijacker/get-rid-counter-yadro-ru&lt;/SPAN&gt;&lt;/A&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;SPAN style="color: windowtext;"&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: windowtext;"&gt;Kindly suggest/help to create DNS lookup block IPS rule for the above domain.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: windowtext;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: windowtext;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: windowtext;"&gt;Ramachandran&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;SPAN style="color: windowtext;"&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jun 2017 20:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075516#M17701</guid>
      <dc:creator>ramachandran.gunasekaran</dc:creator>
      <dc:date>2017-06-18T20:56:47Z</dc:date>
    </item>
    <item>
      <title>If it's not already being</title>
      <link>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075517#M17702</link>
      <description>&lt;P&gt;If it's not already being blocked by the Global Blacklist feed then you can create and add a custom DNS blacklist locally (under object management).&lt;/P&gt;
&lt;P&gt;Make sure it is specified in your DNS policy and that DNS policy is called out in the Access Control Policy. Finally, deploy the policy.&lt;/P&gt;
&lt;P&gt;Reference:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/DNS_Policies.html#concept_FFB4BE7AF2914BAD9CFF278BCCBC523C&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/fmc_dns_policy.png" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 11:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075517#M17702</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-19T11:54:46Z</dc:date>
    </item>
    <item>
      <title>Thanks for the response.</title>
      <link>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075518#M17703</link>
      <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;
&lt;P&gt;There were successful connections before blocking this domain in proxy but we still see proxy and ips log towards the "counter.yadro.ru".&lt;/P&gt;
&lt;P&gt;If possible, can you share us much more info regarding the same. Need to troubleshoot the system from which we use logs for this domain.&lt;/P&gt;
&lt;P&gt;The suspected part is eventhough there is no redirection observed proxy ips logs towards this domain.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Ramahandran&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 20:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075518#M17703</guid>
      <dc:creator>ramachandran.gunasekaran</dc:creator>
      <dc:date>2017-06-19T20:58:57Z</dc:date>
    </item>
    <item>
      <title>I'm not sure how your entire</title>
      <link>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075519#M17704</link>
      <description>&lt;P&gt;I'm not sure how your entire flow works between DNS server, web proxy and IPS. As long as the endpoints have the malware on them they will make attempts to lookup the domain.&lt;/P&gt;
&lt;P&gt;Part of the IPS or web proxy blocking them (if that is indeed what is happening) would be to log the aciton of having blocked it. That is normal and expected.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 04:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075519#M17704</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-20T04:14:56Z</dc:date>
    </item>
    <item>
      <title>Can you able to help with us</title>
      <link>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075520#M17705</link>
      <description>&lt;H2 style="line-height: normal; text-autospace: none; margin: 2.0pt 0in 2.0pt 0in;"&gt;&lt;SPAN style="font-size: 14pt; font-family: times new roman,times,serif;"&gt;Can you able to help with us by providing &lt;SPAN style="color: black;"&gt;custom signatures for our environment. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H2&gt;</description>
      <pubDate>Thu, 22 Jun 2017 20:34:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075520#M17705</guid>
      <dc:creator>ramachandran.gunasekaran</dc:creator>
      <dc:date>2017-06-22T20:34:48Z</dc:date>
    </item>
    <item>
      <title>No. This is the free Cisco</title>
      <link>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075521#M17706</link>
      <description>&lt;P&gt;No. This is the free Cisco Support Community. That would be outside the scope of what this community is for.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 12:33:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075521#M17706</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-23T12:33:04Z</dc:date>
    </item>
    <item>
      <title>Thank you so much for the</title>
      <link>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075522#M17707</link>
      <description>&lt;P&gt;Thank you so much for the support&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 00:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blacklist-dns-request-for-known-malware-domain-counter-yadro-ru/m-p/3075522#M17707</guid>
      <dc:creator>ramachandran.gunasekaran</dc:creator>
      <dc:date>2017-06-28T00:19:31Z</dc:date>
    </item>
  </channel>
</rss>

