Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
D_W
Advisor

explain TP Log

Hi Mates,

please can someone explain this log entry?

I understand what happened, the client tried to reach a C&C Server "dopla.com.pl" and the CP replaced the DNS entry with the bogus IP.

But why do we see shodan.io URLS in the forensic info on the left side and why is the protection name: "Conficker..."

image.png

0 Kudos
2 Replies
G_W_Albrecht
Legend Legend
Legend

This is used when a lookup of an IP address is needed: https://community.checkpoint.com/t5/Management/SmartView-and-Custom-Actions/m-p/68563#M10382

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
yalmog
Employee
Employee

The default behavior of DNS reputation is to return this bogus ip (62.0.58.94) as a reply to bot DNS request (for name "dojo.census.shodan.io"). This (dst) ip is later detected and blocked on the above https traffic.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events