The last 2 days we are getting constant notifications of clients and servers attempting to reach to a "command and control" server of:
216.239.36.21
The entire 216.239.32.0/19 block is owned by Google, and it appears this address is used for the Google.com site.
http://216.239.36.21
No blacklist is even showing this IP as threat, so I am not sure where this is coming from.
https://www.cyren.com/security-center/cyren-ip-reputation-check
https://mxtoolbox.com/SuperTool.aspx?action=blacklist%3a216.239.36.21&run=toolpage
This thread was automatically locked due to age.