Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Advanced Threat - Is this a false positive?

Got several alerts from different areas this morning with ATP being tripped.

What happened: Sophos Firewall detected malicious connections: 'C2/Generic-C' at 'C:\program files (x86)\Google\Chrome\application\chrome.exe' (Technical Support reference: 0)

Looking at firewall logs the IP that is being flagged is: 199.59.242.153

Anyone else, is this a false positive?



This thread was automatically locked due to age.
Parents
  • My 2 cents -- we're seeing this at a number of sites, it appears a marketing site called mapitquick.net --- the links embedded on some popular site out there) uses this IP for tracking purposes, etc. -- frankly we are just blocking the domain to prevent the annoying messages from popping up, frankly in this case probably a false positive, but do your own investigation.

    Meant to add -- this IP is probably a load balancer IP, etc. and maybe shares its use with another site that maybe was malicious, who knows.  Won't be the first time I've seen ATP freak out in this manner.

Reply Children