Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Advanced Threat Protection

Hello,

In last couple of days i start receive emails from my Sophos UTM (Firmware version 9.350-12)

A threat has been detected in your network The source IP/host listed below was found to communicate with a potentially malicious site outside your company.

Details about the alert:

Threat name....: C2/Generic-A

Details........: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/C2~Generic-A.aspx

Time...........: 2016-03-20 06:41:17

Traffic blocked: yes

Source IP address or host: 218.60.112.225

Every Email include different IP Address but it's not my LAN Network. How i can find problematic machine (IP) from my local network ?



This thread was automatically locked due to age.
Parents
  • Have the same issue I am now tracing DNS logs because the query is coming from my internal DNS server going to specific addresses which is I think from china.

     

    1
     
    bakjjmkiw.ws
    C2/Generic-A
    AFCd
    2016-11-16 18:57:48
    1
    0.58
    1
    0.58
    2
     
    bredpump.info
    C2/Generic-A
    AFCd
    2016-11-16 18:47:55
    1
    0.58
    1
    0.58
    3
     
    buoxlyw.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:56:40
    1
    0.58
    1
    0.58
    4
     
    cajusst.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:48:14
    1
    0.58
    1
    0.58
    5
     
    cawskq.ws
    C2/Generic-A
    AFCd
    2016-11-16 20:00:31
    1
    0.58
    1
    0.58
    6
     
    cjzyrx.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:09:48
    1
    0.58
    1
    0.58
    7
     
    cuolcsfay.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:49:57
    1
    0.58
    1
    0.58
    8
     
    cysooechujg.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:00:17
    1
    0.58
    1
    0.58
    9
     
    dwohtolv.cn
    C2/Generic-A
    AFCd
    2016-11-16 18:47:15
    1
    0.58
    1
    0.58
    10
     
    fhavidw.cn
    C2/Generic-A
    AFCd
    2016-11-16 19:36:05
    1
    0.58
    1
    0.58
    11
     
    frherhue.cn
    C2/Generic-A
    AFCd
    2016-11-16 19:47:50
    1
    0.58
    1
    0.58
    12
     
    fsbeaa.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:20:06
    1
    0.58
    1
    0.58
    13
     
    gmlcgvkiy.ws
    C2/Generic-A
    AFCd
    2016-11-16 18:43:20
    1
    0.58
    1
    0.58
    14
     
    gvxyfamgwvw.info
    C2/Generic-A
    AFCd
    2016-11-16 19:04:14
    1
    0.58
    1
    0.58
    15
     
    hbjmriz.cn
    C2/Generic-A
    AFCd
    2016-11-16 19:49:33
    1
    0.58
    1
    0.58
    16
     
    hcaxbgugl.cn
    C2/Generic-A
    AFCd
    2016-11-16 20:04:52
    1
    0.58
    1
    0.58
    17
     
    jdztlddtd.cn
    C2/Generic-A
    AFCd
    2016-11-16 18:55:46
    1
    0.58
    1
    0.58
    18
     
    jkyatszhco.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:18:11
    1
    0.58
    1
    0.58
    19
     
    jnnznesl.cn
    C2/Generic-A
    AFCd
    2016-11-16 19:27:19
    1
    0.58
    1
    0.58
    20
     
    kujil.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:22:19
    1
    0.58
    1
    0.58
Reply
  • Have the same issue I am now tracing DNS logs because the query is coming from my internal DNS server going to specific addresses which is I think from china.

     

    1
     
    bakjjmkiw.ws
    C2/Generic-A
    AFCd
    2016-11-16 18:57:48
    1
    0.58
    1
    0.58
    2
     
    bredpump.info
    C2/Generic-A
    AFCd
    2016-11-16 18:47:55
    1
    0.58
    1
    0.58
    3
     
    buoxlyw.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:56:40
    1
    0.58
    1
    0.58
    4
     
    cajusst.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:48:14
    1
    0.58
    1
    0.58
    5
     
    cawskq.ws
    C2/Generic-A
    AFCd
    2016-11-16 20:00:31
    1
    0.58
    1
    0.58
    6
     
    cjzyrx.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:09:48
    1
    0.58
    1
    0.58
    7
     
    cuolcsfay.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:49:57
    1
    0.58
    1
    0.58
    8
     
    cysooechujg.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:00:17
    1
    0.58
    1
    0.58
    9
     
    dwohtolv.cn
    C2/Generic-A
    AFCd
    2016-11-16 18:47:15
    1
    0.58
    1
    0.58
    10
     
    fhavidw.cn
    C2/Generic-A
    AFCd
    2016-11-16 19:36:05
    1
    0.58
    1
    0.58
    11
     
    frherhue.cn
    C2/Generic-A
    AFCd
    2016-11-16 19:47:50
    1
    0.58
    1
    0.58
    12
     
    fsbeaa.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:20:06
    1
    0.58
    1
    0.58
    13
     
    gmlcgvkiy.ws
    C2/Generic-A
    AFCd
    2016-11-16 18:43:20
    1
    0.58
    1
    0.58
    14
     
    gvxyfamgwvw.info
    C2/Generic-A
    AFCd
    2016-11-16 19:04:14
    1
    0.58
    1
    0.58
    15
     
    hbjmriz.cn
    C2/Generic-A
    AFCd
    2016-11-16 19:49:33
    1
    0.58
    1
    0.58
    16
     
    hcaxbgugl.cn
    C2/Generic-A
    AFCd
    2016-11-16 20:04:52
    1
    0.58
    1
    0.58
    17
     
    jdztlddtd.cn
    C2/Generic-A
    AFCd
    2016-11-16 18:55:46
    1
    0.58
    1
    0.58
    18
     
    jkyatszhco.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:18:11
    1
    0.58
    1
    0.58
    19
     
    jnnznesl.cn
    C2/Generic-A
    AFCd
    2016-11-16 19:27:19
    1
    0.58
    1
    0.58
    20
     
    kujil.ws
    C2/Generic-A
    AFCd
    2016-11-16 19:22:19
    1
    0.58
    1
    0.58
Children
No Data