Can someone suggest why the ATP would report an infection coming from an external address ?
Thanks
This thread was automatically locked due to age.
Can someone suggest why the ATP would report an infection coming from an external address ?
Thanks
we have the same warning since yesterday
and if i reset the warning it pups up again every few hours
and if i take look at the firewall log i see the last 3 entries are from an internal client to this IP 195.62.53.168 over Port 137.
so i scanned this internal computer for virues and none of 4 av scanners did find anything.
should i be worried?
I'm not seeing these NETBIOS calls at any customer site. I am seeing HTTP/S responses where NAT is in use instead of Webserver Protection.
I'd be tempted to do a packet capture of that traffic to see what's being requested. Since this just started in the last few days, I wouldn't be surprised if the scanners can't see the problem yet.
Cheers - Bob
I'm not seeing these NETBIOS calls at any customer site. I am seeing HTTP/S responses where NAT is in use instead of Webserver Protection.
I'd be tempted to do a packet capture of that traffic to see what's being requested. Since this just started in the last few days, I wouldn't be surprised if the scanners can't see the problem yet.
Cheers - Bob