- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- explain TP Log
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
explain TP Log
Hi Mates,
please can someone explain this log entry?
I understand what happened, the client tried to reach a C&C Server "dopla.com.pl" and the CP replaced the DNS entry with the bogus IP.
But why do we see shodan.io URLS in the forensic info on the left side and why is the protection name: "Conficker..."
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is used when a lookup of an IP address is needed: https://community.checkpoint.com/t5/Management/SmartView-and-Custom-Actions/m-p/68563#M10382
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The default behavior of DNS reputation is to return this bogus ip (62.0.58.94) as a reply to bot DNS request (for name "dojo.census.shodan.io"). This (dst) ip is later detected and blocked on the above https traffic.
