This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

C2/Generic-A Originating from AFCd?

Hi everyone, looks like I have a similar situation to a few people.

NO Windows machines on the network, just OSX and Linux (QNAP).   Woke up to over 1400 emails regarding ATP C2/Generic-A.   But the originiating seems to be from AFCd?  Any idea what this is?

Googling has given me no ideas.    Any ideas anyone?



This thread was automatically locked due to age.
Parents
  • We got some of these today when a Mac user visited a Free Fonts Download site. He went back a 2nd time to show me what he'd done, hence the 2nd round of logged events 18 minutes after the first. That 2nd visit also delivered an JS CoinMiner file as a bonus. The events were also reported against our DNS server. These do not look much like false positives.

Reply
  • We got some of these today when a Mac user visited a Free Fonts Download site. He went back a 2nd time to show me what he'd done, hence the 2nd round of logged events 18 minutes after the first. That 2nd visit also delivered an JS CoinMiner file as a bonus. The events were also reported against our DNS server. These do not look much like false positives.

Children
No Data