cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
69
Views
0
Helpful
1
Replies

Malware / Botnet Activity

jasc79
Level 1
Level 1

Hello ! 

 

We've been using OpenDNS at my small office for many months now. I just logged in to check on it, and my dashboard says Malware/Botnet actvity detected.  However, when I try to filter malware domains, there is nothing listed.

Would a large amount of syncing traffic cause this? We have about 10 users all pushing dropbox files all day, and a VPN. 

Trying to narrow down if I actually have a problem or not. 

1 Reply 1

rotblitz
Level 6
Level 6

"However, when I try to filter malware domains, there is nothing listed."

This can have several reasons:

  • You use a free OpenDNS Home or free Premium DNS account where stats are stored for 14 days only and automatically stop collecting if you didn't visit them within 14 days.  The stats will start collecting again as soon as you visit them.  Latest 24 hours later you'll see something.
  • The incident with the Malware/Botnet activity was/is outside the 14 day range of stats storage of free accounts.
  • You don't have stats and logs enabled at all.

"Would a large amount of syncing traffic cause this?"

What is "syncing traffic"?  Large amount of DNS traffic?  No.  And other kind of traffic like "syncing traffic" (whatever this could mean) is not visible for a DNS service, just for your ISP and the destinations you connect to.