Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM9 blocking Botnet traffic... but EP not finding anything...

I'm getting regular notifications that the firewall is blocking one of my systems from communicating with a known botnet site... but when I run an AV scan on that system it's coming up empty.  Any suggestions regarding 'step b'?  I'm trying other av and am products now to see if anyone else catches it - so far nothing is.  

UTM flags as 'C2/Generic-A' to destination 82.211.30.241 (IPTables).


This thread was automatically locked due to age.
Parents
  • Hmmm, so the hackers of the Chinese military have succeeded in planting a Trojan in the "Made in Taiwan" QNAP firmware?  Should we be surprised?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hmmm, so the hackers of the Chinese military have succeeded in planting a Trojan in the "Made in Taiwan" QNAP firmware?  Should we be surprised?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data