Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Kevin_T600
Contributor
Jump to solution

Anti-bot events today 12-19

Anyone else running into a bunch of anti-bot detection events today? All of a sudden we have 80+ clients logging anti-bot detection events. Services flagged are svchost/chrome/IE. 

Most are tagged as Phising_website.bynzq

Trying to work with support, but they seem overwhelmed and don't have anyone available. 

Curious if anyone else has seen these today. 

1 Solution

Accepted Solutions
Kevin_T600
Contributor

Turns out it was indeed a false positive, that impacts all version of the clients. Will be fixed in version 80.90 I guess. The fix I was given was to update all the clients to that version whenever it come out. 

Apparently R&D found out about it yesterday afternoon, sadly that didn't get shared with support or Incident Response until overnight. 

View solution in original post

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

Can you send me the TAC case you opened in a PM?

0 Kudos
Kevin_T600
Contributor

sent a message:

As an update, it appears all of the events are trying to go to the same destination:

  ord30s26-in-f238.1e100.net    (216.58.192.238)

That appears to be a google hosted site, and virus total has it checked as clean. Not sure why Endpoint is flagging that activity, looks like a false positive, but trying to verify that.

0 Kudos
PhoneBoy
Admin
Admin

Can you post a screenshot of the blocks you're seeing?

0 Kudos
Kevin_T600
Contributor

Turns out it was indeed a false positive, that impacts all version of the clients. Will be fixed in version 80.90 I guess. The fix I was given was to update all the clients to that version whenever it come out. 

Apparently R&D found out about it yesterday afternoon, sadly that didn't get shared with support or Incident Response until overnight. 

0 Kudos
PhoneBoy
Admin
Admin

I was told the same thing through my contacts.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events