Recently, we've received suspicious Internet sites access (see below sites) attempts on server installed after installed the Template for Citrix XenApp. I'd like to know is it possible to eliminate it and how can I fix it. Many thanks!
18.104.22.168 akamai 22.214.171.124 NHN Japan 126.96.36.199 akamai 188.8.131.52 akamai 184.108.40.206 akamai 220.127.116.11 Verizon Business 18.104.22.168 Verizon Business 22.214.171.124 akamai 126.96.36.199 Verizon Business 188.8.131.52 EXPEDIA.COM
You can run the PowerShell scripts from the command line outside of Splunk to see if anything is wrong there. Also, make sure something hasn't hijacked the actual .ps1 files in
You can also compare what you have to the source located at:
We've seen it on the firewall log and the Internet access attempts stopped after we add the %splunkhomefolder%\etc\apps\TA-XA6x-Server\local\app.conf and with the statement "state = disabled". The Internet access attempts resume right after I change the statement to "state = enabled". And I can see the attempts are generated by Powershell.exe via port 80. Any clues? Many thanks!