I am seeing a lot of traffic being identified as malware.azjf C2 traffic over the last couple of days since the last threat update. I have noticed a pattern that users are visiting Wordpress websites that use the owl carousel plugin and checking these sites on VT they come up clean so appears to be a false positive.
Is anyone else aware of this going on?
I have came across one from 17 November 2021. Same here, it points to a WordPress site with a carousel plugin.
Here are the IOCs:
IP: 126.96.36.199 on port 443
Same here. I have hits for at least the following sites,(likely more though), however the commonality seems to be the carousel plugin.
As far as I can tell, this is not malicious traffic, rather a false positive match for C2 traffic.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!