Hi all.
Our Active Directory system using Window Server 2008 R2 Ent that include DNS and DHCP services. Few day ago, Checkpoint firewall deteted http request send from AD server to foreing IP (37.59.200.31). When we tracer what process call this request, it is lsass.exe system process. So, we checked lsass.exe file on virustotal.com , but nothing detected ? pls help us to explain this symptom and closing this request.
Thanks.