Hello, I turned on traffic filtering on our firewall and am trying to identify the traffic that Sophos is Labeling pCloud. There is a pCloud.com Backup and storage
When I attempt to login connect to one of the hosts https://52.20.148.96/ it throws a warning and when I look at the certificate, the certificate is Agent.Jumpcloud.com. Since it is on all our machines and the Certificate is for agent.jumpcloud.com it seems legitimate. Lots of systems have a steady amount of traffic with this App name. The IP addresses are all in AWS and all have the agent.jumpcloud.com SSL certificate. So I am confident that this is our Jumpcloud agents calling home.
At first, I thought it might be a widespread infection sending data to cloud storage.
Is there a process on the Sophos to refine the Application Details? Is there a way to know what causes the traffic to be labelled pCloud.
Best,
Tom
Application Detail Name pCloud
Category Storage and Backup
Risk Medium
Characteristics Transfer files,Prone to misuse,Widely Used
Technology Browser Based
Dependency None
Applicable on 16.01.0 Build 101 and above
Description This indicates pCloud website or application access attempt from the network.
This thread was automatically locked due to age.