Abuse Message [AbuseID:9E3D41:1D]: AbuseNormalMail: [Autoreporter 8afa4e19-1847-4052-a607-bfb5d55ddae9] Summary of your network security incidents (Hetzner)

We have received information regarding spam and/or abuse from ncsc-fi-autoreporter@traficom.fi.
Please would you take all necessary measures to avoid this in the future.

We also request that you send a short response within 24 hours. This response should contain information about how this could have happened and what you intend to do about it.

Information:
——BEGIN PGP SIGNED MESSAGE——
Hash: SHA512

NCSC-FI has received information regarding IP-addresses in your network which may have security problems. The information regarding the problems is included as an attachment in CSV format. Data lines have the following format:
asn|ip|source time|domain name|cc|type|uuid|info

Here cc refers to the country code, type to the type of the security problem, and uuid is the unique identifier of the event in Autoreporter. The info column is reserved for any additional information. The column always includes an anonymous identifier for the datasource that is used in the report. All timestamps are given in UTC.

This report is electronically signed using the PGP-key of Autoreporter. The key is available at
https://www.kyberturvallisuuskeskus.fi/sites/default/files/media/file/NCSC-FI_AUTOREPORTER_2019-2024.txt

For more information on the reported events please contact NCSC-FI at cert@traficom.fi.

Network:
— — asn: 24940
— — ip range:

Report:
— — start UTC time: 2022-01-20 07:00:04Z
— — end UTC time: 2022-01-21 07:00:06Z
asn|ip|source time|domain name|mail cc|type|uuid|info

24940|135.181.118.238|2022-01-20 01:35:45Z||FI|bot|23e5ec1f-06c1-49f0-bdf8-4b5222befbbc|Datasource: b, Malware: avalanche, C&C Ip: 216.218.135.114, C&C Port: 80, Source Port: 49745,,,,

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *