- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- geo-um.btrll.com Suspicious Activity
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
geo-um.btrll.com Suspicious Activity
Hi,
We are getting Suspicious web browsing activity report from Threat prevention and the URL which hits almost all users are geo-um.btrll.com. However action is showing blocked and Category is Botnets.
Anyone has idea about this? What are the precautions need to take.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First of all this is a https://community.checkpoint.com/community/threat-prevention?sr=search&searchId=efab83ed-7362-4a86-b... topic.
Second, it depends on the nature of the traffic.
What's it showing in the logs?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
We are having this same issue and getting a lot of matches under botnet category.
Is there an update that has been pushed or anything else
Sajid
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I have gone through detailed user activity report and found that during this time mostly advertising URLs were opened which adds Popups / cookies and redirects to other URLs which is harmful.
This will not catch in Antivirus so need to remove those processes & Cookies to rectify the things.
