cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1170
Views
0
Helpful
2
Replies

Botnet Filter on ASA complaining about 63.251.179.49

Ronald Nutter
Level 1
Level 1

Anybody running the Botnet filter seeing this address ?

Anyone have any info on this ?

This is showing as a very high threat - Bot & Threat Networks.

Ron

1 Accepted Solution

Accepted Solutions

clausonna
Level 3
Level 3

BTF says this is Conficker, but that data seems to be from 2009 and the IP address is no longer hosting anything.

VPNASA# dynamic-filter database find 63.251.179.49

63.251.179.49  m=WbnpConficker

Found 1 matches

Still, I would suggest investigating the host(s) that are initiating the requests - they might be infected. 

View solution in original post

2 Replies 2

Parminder Sian
Level 1
Level 1

Hi Ronald,

This IP is managed by United States                  Stateline                  Almar Networks Llc.

http://whois.domaintools.com/63.251.179.49

Hope this helps,

Sian

clausonna
Level 3
Level 3

BTF says this is Conficker, but that data seems to be from 2009 and the IP address is no longer hosting anything.

VPNASA# dynamic-filter database find 63.251.179.49

63.251.179.49  m=WbnpConficker

Found 1 matches

Still, I would suggest investigating the host(s) that are initiating the requests - they might be infected. 

Review Cisco Networking products for a $25 gift card