11-13-2012 09:57 AM - edited 03-11-2019 05:22 PM
We have been running the Cisco Botnet fliters for some time now and we are seeing thousands of dropped packets all pointing to backplane1.janrainbackplane.com, port 443 on a wide variety of ip addresses. I can find no information within the other anti-malware vendors that they consider this to be malware. Is this behavior unique to my environment or are you seeing this type of behavior as well?
11-13-2012 11:11 AM
Just to chime in.
Typically those are good reference pages:
http://www.siteadvisor.com/sites/backplane1.janrainbackplane.com
http://www.mywot.com/en/scorecard/backplane1.janrainbackplane.com
http://www.google.com/safebrowsing/diagnostic?site=backplane1.janrainbackplane.com
11-28-2012 09:36 AM
90% of the blocked IPs on my Botnet filter are from backplane1.janrainbackplane.com, port 443
None of the hosts, perhaps 50, have complained about problems.
I have no idea why.
-Robert
11-28-2012 11:57 AM
I currently have an open ticket with Cisco on this matter. I am seeing this "domain" associated with multiple ips. Their current response is
"the domain is mapped to several IPs and due to the command 'dynamic-filter ambiguous-is-black' then it will be blocked. You can create an entry under the White-list in order to access the Website and keep the "ambiguous" command on."
The ip addresses I checked that were being associated with this domain are part of Amazon's e-commerce space. I have white-listed it in a couple of ASAs to see if the underlying ip addresses are captured by the botnet filter.
12-01-2012 06:59 PM
I think these are all pop-up ads. I thought about white-listing, but we've been blcking thousands of hits with no complaints.
We've seen pop up ads that contain malware, so unless someone complains, we'll not white-list.
What is ambiguoius, I wonder? There is no forward - reverse lookup matches for all of these IPs?
12-17-2012 12:08 PM
Same here. We've been blocking about 300-400k connections per day to this site for weeks. Zero complaints. I did a capture and it seemed related to either ads or analytics for Fox Sports websites.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide