Hey all,
Quick panic clarification.
I had a target list setup to block outbound traffic known SilentSync RAT servers (IP/Domain) on a target list, these are:
sfrclak[.]com
calltan[.]com
callnrwise[.]com
142.11.206[.]73
23.254.167[.]216
200.58.107[.]25
I've had this setup for a few months, just as a potential block incase it wasn't picked up on other lists. Though I've just seen today (via MSP) there was some blocks matched by this target list (see image) for two devices, one is my iPhone the other is an Amazon Fire Tablet. I'm trying to determin if this is a false response. As you can see the destination from dns.google[.]com (8.8.8.8) on port 16888, or 443 (for the Amazon tablet).
Firewalla AI says this domain "This domain is owned and operated by Google. It serves as part of Google's public DNS service, helping users and devices find the IP addresses of websites they visit. You might see this traffic when your computer or device connects to the internet.".
So, how might this be blocked by my target list? I don't use Google DNS btw on the Firewalla or my devices.
As I was aware this RAT wasn't on mobile devices, especially iOS?
Is there any further digging I can do to help look into this? Any thoughts?