Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Advanced Threat Protection: False positive to Google owned IP address?

The last 2 days we are getting constant notifications of clients and servers attempting to reach to a "command and control" server of:

216.239.36.21

The entire 216.239.32.0/19 block is owned by Google, and it appears this address is used for the Google.com site.

http://216.239.36.21

No blacklist is even showing this IP as threat, so I am not sure where this is coming from.

https://www.cyren.com/security-center/cyren-ip-reputation-check

https://mxtoolbox.com/SuperTool.aspx?action=blacklist%3a216.239.36.21&run=toolpage



This thread was automatically locked due to age.
Parents Reply Children
No Data