<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS queries in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-queries/m-p/3907395#M925374</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;During work , i have noticed a few DNSQuerys from&amp;nbsp; &lt;A title="cisco:firepower" href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691620.2858610#" target="_blank" rel="noopener"&gt;cisco:firepower&lt;/A&gt;&amp;nbsp;such as :&lt;BR /&gt;&lt;SPAN&gt;\xB8WA\xF1\xCE#024&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-5d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691564.2858522#" target="_blank" rel="noopener"&gt;\xB8\x87Q2z#024&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691620.2858610#" target="_blank" rel="noopener"&gt;\xF8WA\xF1\xCE#024&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691620.2858610#" target="_blank" rel="noopener"&gt;\xB8WA\xF1\xCE#024&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691620.2858610#" target="_blank" rel="noopener"&gt;\xC8WA\xF1\xCE#024&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;I tried searching this type of DNS Queries and didn't find an explanation&lt;BR /&gt;Any chance I could decode it for something readable, I need to know where it resolves.&lt;BR /&gt;It was forwarded to&amp;nbsp;upstream DNS&amp;nbsp;8.8.4.4,&amp;nbsp;8.8.8.8&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 17:23:41 GMT</pubDate>
    <dc:creator>DavidShoshany5376</dc:creator>
    <dc:date>2020-02-21T17:23:41Z</dc:date>
    <item>
      <title>DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/dns-queries/m-p/3907395#M925374</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;During work , i have noticed a few DNSQuerys from&amp;nbsp; &lt;A title="cisco:firepower" href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691620.2858610#" target="_blank" rel="noopener"&gt;cisco:firepower&lt;/A&gt;&amp;nbsp;such as :&lt;BR /&gt;&lt;SPAN&gt;\xB8WA\xF1\xCE#024&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-5d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691564.2858522#" target="_blank" rel="noopener"&gt;\xB8\x87Q2z#024&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691620.2858610#" target="_blank" rel="noopener"&gt;\xF8WA\xF1\xCE#024&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691620.2858610#" target="_blank" rel="noopener"&gt;\xB8WA\xF1\xCE#024&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://10.1.5.90:8000/en-US/app/search/search?q=search%20index%3Dnetwork%20sourcetype%3Dcisco%3Afirepower%20DNSQuery%3D%22*%5C%5C*%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d&amp;amp;latest=now&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22virusFileName%22%2C%22Virus%20Location%22%2C%22vulnerabilityName%22%2C%22blockuri%22%5D&amp;amp;sid=1565691620.2858610#" target="_blank" rel="noopener"&gt;\xC8WA\xF1\xCE#024&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;I tried searching this type of DNS Queries and didn't find an explanation&lt;BR /&gt;Any chance I could decode it for something readable, I need to know where it resolves.&lt;BR /&gt;It was forwarded to&amp;nbsp;upstream DNS&amp;nbsp;8.8.4.4,&amp;nbsp;8.8.8.8&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-queries/m-p/3907395#M925374</guid>
      <dc:creator>DavidShoshany5376</dc:creator>
      <dc:date>2020-02-21T17:23:41Z</dc:date>
    </item>
  </channel>
</rss>

