Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Akamaitechnologies - malware?

I work at a university with a good network and admins. Their intrusion detection system blocked my MAC address with this snippet of an explanation:


MALWARE TRAFFIC DETECTED: 2015-02-05-00:32:30 UTC [**] [1:2020347:3]CUSTOMSEC -- AUTOBLOCKSAFE -- CURRENT_EVENTS Chaintor/Tordal User-Agent spotted downloading payload [**] [Classification: A Network Trojan was Detected] [Priority: 1] {TCP} w.x.y.z:49262 -> 72.246.81.207:80


72.246.81.207 is owned my Akamai Technologies. I started monitoring traffic and found each time I launch Safari, my system generated a lot of web traffic to akamaitechnologies.

It's unclear exactly what is being downloaded. Here's an article that suggests it's for QuickTime delivery and other "stuff" http://superuser.com/questions/462495/whats-all-this-deploy-akamaitechnologies-c om-traffic I haven't found an explanation on why Akamai wants to phone home EACH TIME Safari is run.

It's a bit suspicious that the IDS alert came from a totally different subnet. Both are owned by Akamai, but the block suggests a different infrastructure.

CIDR 72.246.0.0/15 - IP address caught by IDS

CIDR 23.0.0.0/12 - Safari traffic


I had a friend close/reopen Safari on his MBP and we found his computer made similar connections to Akamai on the 23/12 network but not the 72.246/15 network.


So ... Did the IDS generate a false positive? Is Akamai serving Apple sanctioned content with viruses? Or is my system infected independently by someone leveraging Akamai? Opinions welcome. I'm 50/50 on reinstalling my OS.


I'm running Yosemite which was, at the time, up to date minus Combined 10.10.2 (a week out of date). No AV.

x86, Mac OS X (10.5.1)

Posted on Feb 6, 2015 4:47 AM

Reply
Question marked as Best reply

Posted on Feb 6, 2015 10:57 PM

Akamai is a content-distribution network used by Apple, Adobe, and many others. It could be used to distribute anything. Most likely this is a false positive.

7 replies

Feb 6, 2015 5:16 AM in response to genkuro

Akamai software is known as "content preloading" software that tries to smooth server loads out and/or make things faster.

I consider it "misguided." It tries to make akamai seem more efficient "at my computer's expense."

There are reports here about this being involved in slowdowns.

"3rd party software downloads" put this on your computer. (including Adobe)

I think the immediate access you mention is about looking for updates.

I presume akamai is being paid for this.

Read about the idea here:

http://www.akamai.com/html/solutions/client_faq.html

https://community.akamai.com/community/web-performance/blog/2015/02

Aug 19, 2015 1:14 AM in response to genkuro

As indicated by Linc Davis, akamaitechnologies.com is used by Apple (and others) as a content delivery network (CDN). iCloud content is stored on Akamai servers. Asuming you are using iCloud, e.g. to store Safari bookmarks, it is normal that opening Safari triggers a connection to Akamai since the actual content (= Safari bookmarks) are physically stored on Akamai distribution servers and needs to be synced when opening the browser.

Sep 29, 2015 7:31 AM in response to fredjason

the last name or word after the last dot (before the .com) is what you need to pay attention to.


for example here are some hypothetical links:

deploy.akamaitechnolgies.com
would resolve to akamaitechnolgies.com

delpoy.static.akamaitechnolgies.com
would also resolve to akamaitechnolgies.com


static.akamaitechnolgies.delpoy.com
would resolve to deploy.com and who are they? Not akamaitechnolgies that's who!


deploy.static.akamaitechnlgies.com would resolve to akamaitechnlgies.com

note the typo, it's not going to akamaitechnolgies.com unless they own akamaitecholgies too and have a redirect for that specific typo.

If they do you would see the domain redirect (in your browser URL bar) to akamaitechnolgies, if not it would say the same (akamaitechnlgies) and I would be very suspicious.

Akamaitechnologies - malware?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.