Comprehensive data protection for all workloads
cparker4486
Expert
Posts: 231 Liked: 18 times
Joined: Dec 07, 2009 5:09 pm
Full Name: Chris
Contact:
Post
by cparker4486 » Sep 23, 2013 5:26 pm
this post
Hi,
I believe this is a false negative but can someone explain why Sonicwall is picking up HTTP requests to mc.yandex.ru from the forum as being botnet activity? Below is a screenshot from wireshark and the text of an alert email I receive from Sonicwall.
Code: Select all
09/23/2013 09:52:18.400 - Alert - Botnet Blocking - Suspected Botnet responder blocked: Responder IP:93.158.134.119 - <my local ip>, 62899, X0, workstation.domain.local (admin) - 93.158.134.119, 62899, X3, mc.yandex.ru -
This email was generated by: SonicOS Enhanced 5.8.1.12-46o (C0EA-E419-C0BC)
-- Chris
Gostev
Chief Product Officer
Posts: 31814 Liked: 7302 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:
Post
by Gostev » Sep 23, 2013 9:35 pm
this post
No idea, but I can confirm that Yandex.ru is legit (top search site in Russia, Google's competitor). I have forwarded this to the web team. Thanks!
cparker4486
Expert
Posts: 231 Liked: 18 times
Joined: Dec 07, 2009 5:09 pm
Full Name: Chris
Contact:
Post
by cparker4486 » Sep 23, 2013 9:48 pm
this post
Hi, Gostev. That's what I thought. I will send this information to SonicWall as well and see if they can't improve their detection rules somehow.
-- Chris
Users browsing this forum: Bing [Bot] , Google [Bot] and 68 guests