<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anti-bot events today 12-19 in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18311#M381</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sent a message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an update, it appears all of the events are trying to go to the same destination:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; background-color: #ffffff;"&gt;&amp;nbsp; ord30s26-in-f238.1e100.net&amp;nbsp; &amp;nbsp; (216.58.192.238)&lt;/SPAN&gt;&lt;BR data-jive-statusinputadd="true" data-jive-truncation-flag="true" style="color: #222222;" /&gt;&lt;BR data-jive-statusinputadd="true" data-jive-truncation-flag="true" style="color: #222222;" /&gt;&lt;SPAN style="color: #222222; background-color: #ffffff;"&gt;That appears to be a google hosted site, and virus total has it checked as clean. Not sure why Endpoint is flagging that activity, looks like a false positive, but trying to verify that.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Dec 2018 01:41:31 GMT</pubDate>
    <dc:creator>Kevin_T600</dc:creator>
    <dc:date>2018-12-20T01:41:31Z</dc:date>
    <item>
      <title>Anti-bot events today 12-19</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18309#M379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone else running into a bunch of anti-bot detection events today? All of a sudden we have 80+ clients logging anti-bot detection events. Services flagged are svchost/chrome/IE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most are tagged as Phising_website.bynzq&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trying to work with support, but they seem overwhelmed and don't have anyone available.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Curious if anyone else has seen these today.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 21:07:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18309#M379</guid>
      <dc:creator>Kevin_T600</dc:creator>
      <dc:date>2018-12-19T21:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-bot events today 12-19</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18310#M380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you send me the TAC case you opened in a PM?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 00:58:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18310#M380</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-20T00:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-bot events today 12-19</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18311#M381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sent a message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an update, it appears all of the events are trying to go to the same destination:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; background-color: #ffffff;"&gt;&amp;nbsp; ord30s26-in-f238.1e100.net&amp;nbsp; &amp;nbsp; (216.58.192.238)&lt;/SPAN&gt;&lt;BR data-jive-statusinputadd="true" data-jive-truncation-flag="true" style="color: #222222;" /&gt;&lt;BR data-jive-statusinputadd="true" data-jive-truncation-flag="true" style="color: #222222;" /&gt;&lt;SPAN style="color: #222222; background-color: #ffffff;"&gt;That appears to be a google hosted site, and virus total has it checked as clean. Not sure why Endpoint is flagging that activity, looks like a false positive, but trying to verify that.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 01:41:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18311#M381</guid>
      <dc:creator>Kevin_T600</dc:creator>
      <dc:date>2018-12-20T01:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-bot events today 12-19</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18312#M382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post a screenshot of the blocks you're seeing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 05:19:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18312#M382</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-20T05:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-bot events today 12-19</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18313#M383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Turns out it was indeed a false positive, that impacts all version of the clients. Will be fixed in version 80.90 I guess. The fix I was given was to update all the clients to that version whenever it come out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparently R&amp;amp;D found out about it yesterday afternoon, sadly that didn't get shared with support or Incident Response until overnight.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 12:07:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18313#M383</guid>
      <dc:creator>Kevin_T600</dc:creator>
      <dc:date>2018-12-20T12:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-bot events today 12-19</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18314#M384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was told the same thing through my contacts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 17:55:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Anti-bot-events-today-12-19/m-p/18314#M384</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-20T17:55:53Z</dc:date>
    </item>
  </channel>
</rss>

