Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

C2/Generic-A

Hi,

Today I our UTM Advenced Threat Protection shows C2/Generic-A drop. the logs has the IP of our DNS server. I did download the  Sophos Virus Removal Tool on the DNS server and run it and it came up clean.

I did enable the DNS debug and find out a host in our network try to access the clonyjohn.com.

Should we also run the Virus Removal Tool on this host as well? Our own Mcafee AV did not come up with any virus.

Thanks



This thread was automatically locked due to age.
Parents
  • Yes you should run multiple tools on that host. Your DNS is probably clean if your clients use your dns server for dns lookups. You did everything correct to identify the source, good job. Tell us if you find something. Maybe it's too early and too much but maybe you have to wipe the client if no tool detects something.

    Best regards

    Alex

    -

  • Hi Alex,

     

    Thanks for your reply,

    I plan to run the Sophos Virus Removal Tool on the host tonight. Any other tool that you can advice us to run on the host?

    Does clonyjohn.com says anthing to you? I ask this becase the ATP logs and DNS debug log show the same domain.

    I cannot ping the clonyjohn.com or run a whois against it, but the DNS debug logs shows this IP 46.165.194.230

    I did check the IP in IP abuse report database and IP came up clean. Also almost all of the packages send is udp.

    Thanks

Reply
  • Hi Alex,

     

    Thanks for your reply,

    I plan to run the Sophos Virus Removal Tool on the host tonight. Any other tool that you can advice us to run on the host?

    Does clonyjohn.com says anthing to you? I ask this becase the ATP logs and DNS debug log show the same domain.

    I cannot ping the clonyjohn.com or run a whois against it, but the DNS debug logs shows this IP 46.165.194.230

    I did check the IP in IP abuse report database and IP came up clean. Also almost all of the packages send is udp.

    Thanks

Children