Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
D_W
Advisor

explain TP Log

Hi Mates,

please can someone explain this log entry?

I understand what happened, the client tried to reach a C&C Server "dopla.com.pl" and the CP replaced the DNS entry with the bogus IP.

But why do we see shodan.io URLS in the forensic info on the left side and why is the protection name: "Conficker..."

image.png

0 Kudos
2 Replies
G_W_Albrecht
Legend
Legend

This is used when a lookup of an IP address is needed: https://community.checkpoint.com/t5/Management/SmartView-and-Custom-Actions/m-p/68563#M10382

CCSE CCTE CCSM SMB Specialist
0 Kudos
yalmog
Employee
Employee

The default behavior of DNS reputation is to return this bogus ip (62.0.58.94) as a reply to bot DNS request (for name "dojo.census.shodan.io"). This (dst) ip is later detected and blocked on the above https traffic.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events