Characteristics
Affected Operating Systems

C2/Generic-A is the threat name associated with the command and control (C&C) servers used by malware.
Note: C2/Generic-A is not detection of a malware payload on an infected machine.
Instead it indicates Sophos products blocking network traffic (reputation or IPS filtering) to a remote machine believed to be a C&C server. The alert indicates that a machine within the network is compromised with malware.
Recommended remediation steps:
-
Identify the compromised machine. The IP address of the machine attempting to connect to the C&C server will be visible within the alert.
- Perform a full system scan on the compromised machine using the Sophos Virus Removal Tool (free download).