This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Drop by Advanced threat protection (ATP)

Hello everyone. Can you help me with this alert?



This thread was automatically locked due to age.
Parents
  • Explanation for most DNS cases....your server most likely is your DC or at least has a DNS server rule. Means your clients requesta internal server, server requesta UTM or public DNS servers. So ATP DNS triggers only on server(s)

    Most likely there's no "infected" client in the network, but a client most likely downloaded a cryptomining script (or at least got a website with a link to download such a script from that webminepool site) during surfing some websites.

    As it got blocked by ATP DNS and the client didn't find a miner (sophos AV is quite good detecting those) there most likely a script was linked in a website for download, and ATP blocked the DNS request. So you're most likely fine, as download was not possible (no DNS resolution, no download)

    Hope that helps

  • I found the station through Sophos Central, thank you guys. Sophos Firewall detected malicious traffic: 'C2 / Generic-C' at 'C: \ Windows \ System32 \ svchost.exe'

  • And was the client infected or "only" trying to connect to c2 / mining domain by accident during websurfing? Just wonder :o))

  • He was really infected. I love Sophos =]

Reply Children
No Data