cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

MALWARE-CNC Torpig bot sinkhole server DNS lookup

antonioa
Level 1
Level 1

I'm trying to figure out an interesting case I have on hand. Our SF IPS-es running on 6.1.0.3 (build 57) are detecting this  CNC torpig bot  sinkhole server DNS lookup events coming from our Internal Barracuda ESGs. We had called Barracuda technical support but they can't find from their side what is causing the issue.  I talked to Cisco TAC and they believe there is a client relaying DNS queries thru these barracuda boxes.  Has anyone experienced this same issue I'm having? 

Who Me Too'd this topic