This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ATP Alerts every 4 - 8 mins.

For the last three hours I have been getting ATP Alerts every 4 - mins.  The trouble is that the source IP keeps changing.  Here is an example.

 

Message........: BROWSER-IE Microsoft Edge App-v vbs command attempt

Details........: https://www.snort.org/search?query=48053

Time...........: 2020-05-12 15:07:12

Packet dropped.: yes

Priority.......: high

Classification.: Attempted User Privilege Gain IP protocol....: 6 (TCP)

 

Source IP address: 23.40.196.9 (a23-40-196-9.deploy.static.akamaitechnologies.com)

Source port: 80 (http)

Destination IP address: 192.168.15.18

Destination port: 53492

 

The internal IP is one of our domain controllers.  I have checks the logs on the DC's but don't see anything.

 

Any ideas?



This thread was automatically locked due to age.
Parents
  • Hi,

    Same issue here since yesterday around 22:00. I think it is related to the KB4556799 windows update of yesterdays Microsofts PatchTuesday. The moment I try to search for updates it is getting blocked. Also all the IP's it tries to get it from are Content delivery network providers (akamai, Highwindsgroup, Edgecast, centurylink etc) which makes sense with windows updates.

    I think this is a false positive.

    Kind Regards

    (edit typos)

Reply
  • Hi,

    Same issue here since yesterday around 22:00. I think it is related to the KB4556799 windows update of yesterdays Microsofts PatchTuesday. The moment I try to search for updates it is getting blocked. Also all the IP's it tries to get it from are Content delivery network providers (akamai, Highwindsgroup, Edgecast, centurylink etc) which makes sense with windows updates.

    I think this is a false positive.

    Kind Regards

    (edit typos)

Children