Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Advanced Threat Protection C2/Generic-A

Hello,

    I am wondering if I am seeing false positives or not?  Every machine in my network hit on an IP address today according to ATP.  the IP address is 205.185.216.10.  Some show as IpTables and others as AFCd.  I checked the Advanced Threat Protection log and I do see the entries since 16:32.  I also checked the Web Filtering Log and I see multiple entries there with that as the destinationIP.  This is seeing the Windows Update application in there.  Though when I do an IP lookup on it, it shows for Highwinds Network group.  I have sent an email to abuse@hwng.net, and am preparing to send an email to Microsoft as it might be possible that Windows Update has been hijacked.

Just not sure if these are legitimate or not.  Plus maybe someone else was seeing the same thing.

 

Thank You.



This thread was automatically locked due to age.
Parents
  • I have four UTMs where the ATP has triggered and they all point to 205.185.216.10.

    Googling that IP address shows that it is considered a malware confirmed IP address by several different sites. All of the source IP addresses going to that IP address have been Windows 10, Windows Server 2019, Windows Server 2012. In some cases, the Windows hosts are protected by Sophos Endpoint and if servers, protected by Intercept-X. In other cases, devices are protected by Kaspersky Small Business Security.

Reply
  • I have four UTMs where the ATP has triggered and they all point to 205.185.216.10.

    Googling that IP address shows that it is considered a malware confirmed IP address by several different sites. All of the source IP addresses going to that IP address have been Windows 10, Windows Server 2019, Windows Server 2012. In some cases, the Windows hosts are protected by Sophos Endpoint and if servers, protected by Intercept-X. In other cases, devices are protected by Kaspersky Small Business Security.

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?