Hi folks,
A little confused. I keep getting warnings for threat detection:
Advanced Threat Protection
A threat has been detected in your network The source IP/host listed below was found to communicate with a potentially malicious site outside your company.
Details about the alert:
Threat name....: C2/Virut-A
Details........: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/C2~Virut-A.aspx
Time...........: 2017-07-12 04:37:24
Traffic blocked: yes
Source IP address or host: 54.84.67.222
System Version : Sophos UTM 9.501-5
When I check in my logs to see what internal host is communicating I see nothing but external reported - how is this happening and how can I track and kill off whatever is happening here?
Would appreciate any insight or advice!!.
Thanks
Chris
This thread was automatically locked due to age.