Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

C2/Zbot-A detected from IP = iphone ?

Hello,

Just curious, I received a warning from my firewall that it detected the C2/Zbot-A C&C virus from an IP that points to my iphone7 (it is NOT hacked, and is fully patched IOS).

 

The only thing in my IPS log is:

"2017:09:07-05:48:08 gateway ulogd[646]: id="2104" severity="info" sys="SecureNet" sub="ips" name="ICMP flood detected" action="ICMP flood" fwrule="60014" initf="eth1" srcmac="88:6b:6e:3c:82:57" dstmac="00:25:90:f2:cb:67"

 action="ICMP flood" fwrule="60014" initf="eth1" srcmac="88:6b:6e:3c:82:57" dstmac="00:25:90:f2:cb:67" srcip="192.168.0.102"

 dstip="192.168.0.1" proto="1" length="1376" tos="0x00" prec="0x00" ttl="64" type="8" code="0" "

 

192.168.0.102 = my iPhone 7+

 

I'm not really sure how to check my iphone to see if its in fact infected with something.  Any suggestions are appreciated.



This thread was automatically locked due to age.