APT Logs Recorded The Blacklisted IP Issue

|
  • 187
  • 8

Issue Description

Blacklisted IP address still recorded and shows in APT logs.


Handling Process

This is a normal phenomenon. when the PC access the domain name of the blacklist IP, PC will send DNS packet to DNS server to resolve the domain name to get the IP. This DNS packet does not contain the blacklist IP only contains a domain name, PC IP, and destination DNS server IP. When the packet reaches the Firewall, the Firewall will record down this domain name in the APT logs. When the DNS server replies the DNS packet contains the blacklist IP, the packet will be drop. Therefore, the APT logs will record down which PC try to resolve the domain name of blacklisted IP but when the PC connect to the blacklist IP, it will be drop.

Root Cause

Usually, the Firewall will drop the packet which contains blacklisted IP. When PC tries to resolve the domain name, the packet does not contain blacklisted IP, therefore, APT logs will record down which PC try to resolve the domain name.

Solution

As a suggestion, please use the botnet detection tool to detect the botnet virus on PC. Link: http://go.sangfor.com/edr-tool-20180824
Faisal Posted 21 Aug 2020 08:14
  
Thank you very much for the information ...
Faisal Posted 22 Oct 2020 12:34
  
Nice article ...
jetjetd Lv5Posted 10 Nov 2020 13:37
  
interesting...
Muhammad Bilal Lv4Posted 06 Dec 2020 18:59
  
great and detailed sharing
Faisal Posted 18 Dec 2020 10:18
  
Great info ...
Ellechar Lv4Posted 26 Jan 2021 14:59
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 19 Mar 2021 07:21
  
Very informative …
Faisal Posted 05 Jun 2021 00:03
  
Nice guidance ...

I want to write a case
Doc ID: 2324
Author: Niubility
Updated: 2019-12-22 18:22
Version: