{"id":9272,"date":"2019-04-08T10:55:41","date_gmt":"2019-04-08T08:55:41","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=9272"},"modified":"2021-06-17T23:04:52","modified_gmt":"2021-06-17T21:04:52","slug":"sophos-false-alarms-april-2019","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/04\/08\/sophos-false-alarms-april-2019\/","title":{"rendered":"Sophos false alarms (April 2019)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">Administrators using Sophos security solutions may have been bothered by a number of false positives alarms within the recent days. If this is fixed now, the reason is known. <\/p>\n<p><!--more--><\/p>\n<p>It's just a brief piece of information I have from last week. The admins of Sophos security solutions received the following warning that a thread (security issue) had been discovered on the network::<\/p>\n<pre>&lt;**[CRIT-861] Advanced Threat Protection Alert**\nAdvanced Threat Protection\nA threat has been detected in your network The source IP\/host listed below was found to communicate with a potentially malicious site outside your company.\nDetails about the alert:\n\nThreat name....: C2\/Generic-A\nDetails........: http:\/\/www.sophos.com\/en-us\/threat-center\/threat-analyses\/viruses-and-spyware\/C2~Generic-A.aspx\nTime...........: 2019-04-04 18:49:03<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/community.sophos.com\/cfs-file\/__key\/communityserver-discussions-components-files\/51\/pastedimage1554500413050v2.png\" width=\"633\" height=\"95\"><br \/>(Source: Sophos)<\/p>\n<p>This weekend I came across this post at administrator.de with a hint to the cause. The whole thing is described in the Sophos forum (Advisory: Sophos UTM &#8211; ATP is blocking traffic to Windows Update server (93.184.221.240)). The background was a blocked IP used by Microsoft Update. Sophos has provided an update which should be installed. Was anyone affected?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Administrators using Sophos security solutions may have been bothered by a number of false positives alarms within the recent days. If this is fixed now, the reason is known.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-9272","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/9272","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=9272"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/9272\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=9272"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=9272"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=9272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}