Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Advanced threat protection

We recently got warning:

 

Advanced Threat Protection

A threat has been detected in your network
The source IP/host listed below was found to communicate with a potentially malicious site outside your company.

Details about the alert:

Threat name....: C2/ZAccess-A (SID: 31136)
Details........: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/C2~ZAccess-A.aspx
Time...........: 
Traffic blocked: yes

Source IP address or host: malware-hunter.census.shodan.io

 

How can we identify source host, because it seems renamed to somehing like malware-hunter.census.shodan.io. It's on UTM9 appliance.



This thread was automatically locked due to age.