We have received information regarding spam and/or abuse from ncsc-fi-autoreporter@traficom.fi.
This is an information email only and does not require any further action on your part.
It is your choice whether or not to investigate the complaint.
We do not expect any response.
Information:
——BEGIN PGP SIGNED MESSAGE——
Hash: SHA512
NCSC-FI has received information regarding IP-addresses in your network which may have security problems. The information regarding the problems is included as an attachment in CSV format. Data lines have the following format:
asn|ip|source time|domain name|cc|type|uuid|info
Here cc refers to the country code, type to the type of the security problem, and uuid is the unique identifier of the event in Autoreporter. The info column is reserved for any additional information. The column always includes an anonymous identifier for the datasource that is used in the report. All timestamps are given in UTC.
This report is electronically signed using the PGP-key of Autoreporter. The key is available at
https://www.kyberturvallisuuskeskus.fi/sites/default/files/media/file/NCSC-FI_AUTOREPORTER_2019-2024.txt
For more information on the reported events please contact NCSC-FI at cert@traficom.fi.
Network:
— — asn: 24940
— — ip range:
Report:
— — start UTC time: 2022-10-09 06:00:07Z
— — end UTC time: 2022-10-10 06:00:06Z
24940|65.108.15.11|2022-10-09 21:27:21Z||FI|bot|f2db3fd2-63a5-40c8-8efc-0fb609facd25|Datasource: l, Malware: generic/avalanche, C&C Ip: 216.218.135.114, C&C Port: 80, Additional Information: B67-SS-GENERIC, Source Port: 54593
24940|65.108.15.11|2022-10-09 23:03:18Z||FI|bot|0b41888b-d053-412f-a1fa-ddd700202538|Datasource: l, Malware: matsnu, C&C Ip: 216.218.185.162, C&C Port: 80, Additional Information: B67-SS-MATSNU, Source Port: 64320
24940|65.108.15.11|2022-10-09 23:03:18Z||FI|bot|ae6fd7d2-0c16-4fac-91a5-ab46834d7d54|Datasource: b, Malware: matsnu, C&C Ip: 216.218.185.162, C&C Port: 80, Source Port: 64317
24940|65.108.15.11|2022-10-09 21:27:21Z||FI|bot|0977ac22-1574-4d3f-9b94-3033059d2531|Datasource: b, Malware: avalanche, C&C Ip: 216.218.135.114, C&C Port: 80, Source Port: 54535
24940|65.108.15.11|2022-10-09 21:32:10Z||FI|bot|a432bb6d-7411-4aa5-8614-b55a921e6e0f|Datasource: b, Malware: sality, C&C Ip: 85.17.31.82, C&C Port: 80, Http Request: HEAD /wp-login.php HTTP/1.1, Source Port: 62605
24940|65.108.15.11|2022-10-09 21:32:10Z||FI|bot|c1bdff7c-455d-4331-ba05-4b10418c87f4|Datasource: b, Malware: sality, C&C Ip: 178.162.217.107, C&C Port: 80, Http Request: HEAD /wp-login.php HTTP/1.1, Source Port: 62608
24940|65.108.15.11|2022-10-09 21:32:10Z||FI|bot|1def94f6-d9f7-4596-a92e-d6f675bb3b1e|Datasource: b, Malware: sality, C&C Ip: 178.162.203.202, C&C Port: 80, Http Request: HEAD /wp-login.php HTTP/1.1, Source Port: 62649