Every once in a while I get a hit in Advanced Threat Protection for C2/Zbot-A. Those are single hits, with pretty benign destinations (usually targetting one of the DNS servers used by our infrastructure).
The first time it happened I scanned the specific machine UTM pointed at and found nothing, and I was sure this was a false positive. However, this keeps coming back - not frequently, mind you, just... once every 2 weeks or so there's another hit.
Is this a false positive? I THINK it's all false positives, because of the following:
C2/Zbot-A will be reported in the following two scenarios:
- Sophos detecting C2/Zbot-A on a configuration file downloaded from the C&C server. The detection may occur on an infected endpoint or on the network (for example the Sophos web appliance or UTM).
- Sophos blocking network traffic (reputation or IPS filtering), where the remote server is reported to be a Zbot C&C server.
Am I right that these are all false positives, or should I be worried? If these ARE false positives, is there any way to prevent this from happening? Getting a warning on a weekend when I'm trying to relax is really not helpful. ;)
This thread was automatically locked due to age.