Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

C2/Generic-A

Hi,

Today I our UTM Advenced Threat Protection shows C2/Generic-A drop. the logs has the IP of our DNS server. I did download the  Sophos Virus Removal Tool on the DNS server and run it and it came up clean.

I did enable the DNS debug and find out a host in our network try to access the clonyjohn.com.

Should we also run the Virus Removal Tool on this host as well? Our own Mcafee AV did not come up with any virus.

Thanks



This thread was automatically locked due to age.
Parents Reply
  • If you wish to identify the source of the callout you could run Process Monitor on the machine and wait for another detection.  Filter the logs for the malicious domain or IP to identify the process or file attempting to access it.  It may also be possible that the domain was accessed from an advertisement on a web page.

Children