This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Advanced Threat Protection

Hello,

In last couple of days i start receive emails from my Sophos UTM (Firmware version 9.350-12)

A threat has been detected in your network The source IP/host listed below was found to communicate with a potentially malicious site outside your company.

Details about the alert:

Threat name....: C2/Generic-A

Details........: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/C2~Generic-A.aspx

Time...........: 2016-03-20 06:41:17

Traffic blocked: yes

Source IP address or host: 218.60.112.225

Every Email include different IP Address but it's not my LAN Network. How i can find problematic machine (IP) from my local network ?



This thread was automatically locked due to age.
Parents
  • Hi, here is our 2 alerts (UTM9 - SG115 / Firmware: 9.355-1):

    Source IP Dest. IP   Threat  Origin First Seen
    180.97.161.227 cZZMebeb6758.app.anmorencai.com C2/Generic-A AFCd 20.3.2016 5:44
    218.60.112.224 Sbxfebeb6758.app.anmorencai.com C2/Generic-A AFCd 20.3.2016 5:31

Reply
  • Hi, here is our 2 alerts (UTM9 - SG115 / Firmware: 9.355-1):

    Source IP Dest. IP   Threat  Origin First Seen
    180.97.161.227 cZZMebeb6758.app.anmorencai.com C2/Generic-A AFCd 20.3.2016 5:44
    218.60.112.224 Sbxfebeb6758.app.anmorencai.com C2/Generic-A AFCd 20.3.2016 5:31

Children
  • I did not do an in depth intel check, but this is what I do have:

    Indicator 218.60.112.225
    Reverse DNS cncln.online.ln.cn
    Country CN
    ASN 4837
    Organization China Unicom Liaoning
    Insights

    DShield has observed IP 218.60.112.225 scanning 227 targets resulting in 1426 reports from 2015-10-20 to 2016-03-22

    Passive DNS (1)
    SourceDomainRecord DataRecord TypeFirst SeenLast Seen
    Spamhaus vip2.alidns.com 218.60.112.225 A 2015-12-01T00:02:07 2015-12-01T00:02:07