Botnetconnectionwarning polyfill.io - some brainstorming please ;-)
Hi folks,
I wonder if I interpret the following right. The "Domain" polyfill.io is listed at Fortiguardservices as "bad" since 26th of June 2024.
See: Threat Signal Report | FortiGuard Labs
We recognized in our FGT, that we have logs about botnet-cc-connections exactly to this domain (polyfill.io). Our investigations show that our DC is trying to lookup the domain. When it tries it, the FGT redirects the request, which is good.
My assumption now is, that our clients (or some of them) are trying to lookup polyfill.io, ask our Domaincontroller/DNS and the DC/DNS is forwarding the request to the provider-dns. Then the FGT blocks it.
As polyfill.io was not "bad" before 26th of june and a lot of websites use the services of polyfill.io i further assume, that our clients are simply surfing to websites, which use this "tool" (polyfill) and then we got the botnetwarning.
We have not found any indication of a infection at our internal computers till now.
So, what do you think? Is my assumption something you say: Yes this is a way it might be, or do you think that this has to be an infection of our internal client(s)?
Thanks!
