This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos ATP DNS dropping * domains

Hi all

We are seeing a lot of dropping from Sophos UTM9 packages (ATP DNS) from *

Someone else?


Looks like it is from Windows Update / Microsoft, but some sites telling its malicious, others not.

Also, I found it:

This thread was automatically locked due to age.
Parents Reply
  • Response from Sophos:

    Thank you for reproting this issue.

    We have updated the ATP signature and it should no longer mark as C2 attack. 

    This IP address is used by Microsoft for windows update.

    Please ensure that pattern updates are up to date if you are still facing the same issue. 
