cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2744
Views
0
Helpful
4
Replies

IP not found in Computers

Hello, 

 

I have a problem with spam mails. 

I have identified the malware (tofsee). I search it in amp console and it shows some files. 

When I search one of them in the section Network Activity -> TCP/IP Streams I see an IP address as a source. 


What is this IP? because it is not of my network

 

When I search for the Internal IP on the computers I do not see any results

 

Any hints?

 

Thanks and regards, 

Konstantinos

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

Can you post the Logs to look and see what you were referring.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello,

To which logs are you referring?

Konstantinos

"Network Activity -> TCP/IP Streams I see an IP address as a source. " - do you have this TCP Stream ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello,

As I understand the Network Activity -> TCP/IP Streams I see are not relevant to my own network, but they are general.
So I do not think they help much.
I will try a different approach to find the cause of the problem.

Regards,
Konstantinos