This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Advanced Threat Protection

Hello,

In last couple of days i start receive emails from my Sophos UTM (Firmware version 9.350-12)

A threat has been detected in your network The source IP/host listed below was found to communicate with a potentially malicious site outside your company.

Details about the alert:

Threat name....: C2/Generic-A

Details........: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/C2~Generic-A.aspx

Time...........: 2016-03-20 06:41:17

Traffic blocked: yes

Source IP address or host: 218.60.112.225

Every Email include different IP Address but it's not my LAN Network. How i can find problematic machine (IP) from my local network ?



This thread was automatically locked due to age.
Parents
  • Same here - I had about 20 of these alerts last night and woke to another 30 more this morning.  I'm seeing it on about a dozen client sites with nothing in common on 3 continents.  The reported addresses are all in the ranges  218.60.112.224 - 227 and 180.97.161.224 - 227.

    To me this looks like a massive scan from China being misreported as an ATP, if it doesn't clear up soon I'll just block the ranges - they are from networks we don't do business with.  

Reply
  • Same here - I had about 20 of these alerts last night and woke to another 30 more this morning.  I'm seeing it on about a dozen client sites with nothing in common on 3 continents.  The reported addresses are all in the ranges  218.60.112.224 - 227 and 180.97.161.224 - 227.

    To me this looks like a massive scan from China being misreported as an ATP, if it doesn't clear up soon I'll just block the ranges - they are from networks we don't do business with.  

Children
No Data