I recently saw a jump in malicious urls in the botnet report with a bunch of entries at confidence 4. I've recently upgraded to 7.0.6 from 6.1.10.
Previous high confidence reports have often shown some malware or other intrusive tracker. These just seem to be ad related. I checked them with the online url category test and they come back as general internet or web, not malicious.
Why does botnet categorize them as malicious url site, but not the url filter?
I've since set up my own custom url cateogry and started loading these in and blocking them to get them off the botnet report. Any downside in doing that? Other than a lot of extra log traffic?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!