• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 102
  • Last Modified:

I have alot of Exchange connections on my DC

I ran a netstat -b on my DC and noticed about 10 connections of  lsass.exe connections going to the foreign address of my Exchange server on ports 8720 and about 10 others in the 20 and 30000 range. Are these common connections of users or an indication of malware? What is the best manual way to find out if malware is acting as a zombie or spam on my network?
1 Solution
IvanSystem EngineerCommented:
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

We Need Your Input!

WatchGuard is currently running a beta program for our new macOS Host Sensor for our Threat Detection and Response service. We're looking for more macOS users to help provide insight and feedback to help us make the product even better. Please sign up for our beta program today!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now