Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

C2/Generic-A

Hi,

Today I our UTM Advenced Threat Protection shows C2/Generic-A drop. the logs has the IP of our DNS server. I did download the  Sophos Virus Removal Tool on the DNS server and run it and it came up clean.

I did enable the DNS debug and find out a host in our network try to access the clonyjohn.com.

Should we also run the Virus Removal Tool on this host as well? Our own Mcafee AV did not come up with any virus.

Thanks



This thread was automatically locked due to age.
Parents Reply
  • To clarify, is the machine a server or client system? Normally on a server nobody uses a web browser for web surfing. So that information can help. And cases of false alarms are rare, but of course possible.

    Of course you could wait a little and see if any more connection attempts will take place.

    -

Children
  • This is server is an RDS server 2012 R2 that some of our customers using it to run our applications on it. some of these users have access to browser (they need it)

    I would like to know which user or what process triggers this. I think I will play a bit with the process monitor and see what we can get out it.