Good morning, Experts!
I came in to work today to find the following in my Advanced Threat Protection logs. The source IP addresses are my internal Active Directory servers (which forward DNS requests out to Google).
I have scanned one of the Active Directory servers listed in the logs with the Sophos Virus Removal Tool, and it reports no infection.
I am guessing that this was a request from a machine on my network. Am I correct, and, if so, how can I find which machine was making the DNS requests?
Any information would be GREATLY appreciated! This is not how I planned on spending my day! :-)
2020:01:14-21:08:28 gateway afcd[12241]: id="2022" severity="warn" sys="SecureNet" sub="packetfilter" name="Packet dropped (ATP)" srcip="xxxxxxxxxxxx" dstip="8.8.8.8" fwrule="63001" proto="17" threatname="C2/Generic-A" status="1" host="xxxxxxxxxxxx" url="-" action="drop"
2020:01:14-21:08:33 gateway afcd[12241]: id="2022" severity="warn" sys="SecureNet" sub="packetfilter" name="Packet dropped (ATP)" srcip="xxxxxxxxxxxx" dstip="8.8.4.4" fwrule="63001" proto="17" threatname="C2/Generic-A" status="1" host="xxxxxxxxxxxx" url="-" action="drop"
This thread was automatically locked due to age.