This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

crl.verisign.com Threat Protection false positives?

Hi all,

We are seeing an increase in ATP notifications just today, in relation to *crl.verisign.com

This seems like its a certificate look up? Mulitplie UTMs are reporting this same threat with different clients, we have run malware bytes and full system AV scan and can't seem to find anything.

The one PC we did find a trojan, we have cleared and just now it has said the same IP tried to get to the same site? the Reason is both DNS and Proxy...


This thread was automatically locked due to age.
Parents
  • Thank you for advice, ondrej 
    I didn´t find nothing with name="web request blocked, threat detected" from todays log.
    I found threat from yesterday log with verisign
    2014:10:06-05:57:07 mail-2 httpproxy[5752]: id="0068" severity="info" sys="SecureWeb" sub="http" name="web request blocked, threat detected" action="block" method="GET" srcip="192.168.100.137" dstip="" user="xx" ad_domain="XX" statuscode="403" cached="0" profile="REF_HttProAccesPolic (Access policy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2582" request="0xa50e550" url="csc3-2009-2-crl.verisign.com/.../Generic-A"


    Maybe today is fixit with new ATP pattern, but why I have still info about 4 botnet traffic client in dashboard.
Reply
  • Thank you for advice, ondrej 
    I didn´t find nothing with name="web request blocked, threat detected" from todays log.
    I found threat from yesterday log with verisign
    2014:10:06-05:57:07 mail-2 httpproxy[5752]: id="0068" severity="info" sys="SecureWeb" sub="http" name="web request blocked, threat detected" action="block" method="GET" srcip="192.168.100.137" dstip="" user="xx" ad_domain="XX" statuscode="403" cached="0" profile="REF_HttProAccesPolic (Access policy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2582" request="0xa50e550" url="csc3-2009-2-crl.verisign.com/.../Generic-A"


    Maybe today is fixit with new ATP pattern, but why I have still info about 4 botnet traffic client in dashboard.
Children