Quantcast
Channel:
Viewing all articles
Browse latest Browse all 120649

Forum Post: RE: C2/Generic-A Originating from AFCd?

$
0
0
Hey Folks, We did some further investigation on that issue and it turned out that it was not related to an ATP pattern update. The cause for the issue happening is due to a botnet, that started to send UDP DNS pakets through malicious domains. Those DNS requests were detected by the ATP rather than being blocked by the packet filter. After the botnet stopped sending DNS requests which stopped ATP reporting the alerts. We are working to improve the paket handling that those kind of traffic will be detected before it reaches the ATP engine. Best regards, Dominic Schmidl

Viewing all articles
Browse latest Browse all 120649

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>