07-18-2023 03:45 PM
Hi there everyone, so over the last few weeks I've noticed and uptick in our FirePower devices sending alerts regarding about various malware/IOC's taking place on one of my web servers. My understanding when reading through these alerts is that someone (the source IP) is attempting to exploit my web server (destination host). I don't believe there to be an actual compromise of the server since the source are the bad actors IP address. When I review the IOC's in FMC, it shows that FMC has dropped the traffic. Here's an example one my most recent attacks:
[1:47299:1] "MALWARE-CNC Win.Trojan.Remcos variant outbound connection" [Impact: Vulnerable] From "FTD" at Tue Jul 18 12:53:47 2023 UTC [Classification: A Network Trojan was Detected] [Priority: 1] {tcp} 139.59.183.83:34488 (united kingdom)->172.21.x.x:80 (unknown).
In this case it's showing that that the source IP 139.59.183.83 is attempting to upload a network trojan to my web server 172.21.x.x over port 80 (we have https redirects in place). Now FMC shows that the inline result states the connection was dropped. Am I understanding this correctly, that the bad actors attempt to upload a network trojan was detected and dropped? And that this in fact an attack being attempted on my web server?
Or is it that something is on my web server is making an outbound call as based on the alert name "...outbound connection". I have reviewed the connection events related to the source IP and they are in-fact showing the inbound connection to my web server was blocked. I just need a bit of a sanity check to make sure my thought process that this attack began from the outside and was blocked by the FW's. I have found no evidence in the connection logs to suggest that the web server is making outbound calls to these malicious IP's.
Solved! Go to Solution.
07-26-2023 03:27 AM
07-26-2023 03:27 AM
08-03-2023 08:35 AM
Thanks for confirming my thoughts on this. I figured that these were blocked inbound attacks, however the way the alerts are worded it makes it sound like there's an active attack taking place.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide