-
Notifications
You must be signed in to change notification settings - Fork 0
/
Test.html
375 lines (374 loc) · 11.9 KB
/
Test.html
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
<html><head>
<style type="text/css" style="display:none"><!-- p { margin-top: 0px; margin-bottom: 0px; } body { padding: 0px; margin: 0px; font-family: Arial; font-size: 12px; color: rgb(0, 0, 0); } .lrm { margin-left: 50px; margin-right: 50px; } .mep { padding-left: 50px; } .shd1 { padding-right: 30px; } .shd2 { padding-right: 40px; } a:link { color: rgb(0, 102, 255); } hr.hr_bottom { color: gray; } h3 { color: rgb(234, 189, 0); font-family: "small-caps bold"; } .Title { color: rgb(234, 189, 0); font-weight: bold; } .bold_detail { font-weight: bold; } .td_first { color: rgb(119, 119, 119); width: 3.5cm; } .ip_blue { color: blue; } .notice { font-size: x-small; } .noticeDetail { font-size: xx-small; } .hrStandard { color: rgb(255, 223, 87); } .maxTest { font-size: 10px; margin-top: 5px; } content { margin-left: 50px; margin-right: 50px; }--></style>
</head>
<body dir="ltr" style="font-size:12pt;color:#000000;background-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;">
<p>?<br>
</p>
<div style="color: rgb(33, 33, 33);">
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> Gene Shin<br>
<b>Sent:</b> Thursday, March 9, 2017 1:10 PM<br>
<b>To:</b> AES US SBU ISOC Cyber Security<br>
<b>Subject:</b> FW: Critical - Symantec Endpoint Reported Infection - Incident 97011834</font>
<div> </div>
</div>
<div><strong>
<div><font face="Tahoma" color="#000000" size="2"> </font></div>
</strong>
<hr tabindex="-1" style="display:inline-block; width:98%">
<font face="Tahoma" size="2"><b>From:</b> SOC Notifications<br>
<b>Sent:</b> Thursday, March 9, 2017 1:10:24 PM (UTC-05:00) Eastern Time (US & Canada)<br>
<b>To:</b> Gene Shin<br>
<b>Subject:</b> Critical - Symantec Endpoint Reported Infection - Incident 97011834<br>
</font><br>
<div></div>
<div>
<table cellpadding="0px" cellspacing="0px" width="100%" height="40px" style="padding:0px; margin:0px">
<tbody>
<tr>
<td background="cid:pageHeaderBG.gif" height="40px">
<table cellpadding="0px" cellspacing="0px" width="686px" height="40px" style="padding:0px; margin:0px">
<tbody>
<tr>
<td background="cid:prodNameBG.gif" height="40px">
<table cellpadding="0px" cellspacing="0px" width="364px" height="27px" style="padding:0px; margin:0px">
<tbody>
<tr>
<td background="cid:HeaderLogo.gif" height="27px"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
<table class="lrm ">
<tbody>
<tr>
<td align="bottom">
<table>
<tbody>
<tr>
<td></td>
</tr>
</tbody>
</table>
<span class="Title">INCIDENT DETAILS</span>
<hr class="hrStandard" size="1">
<table border="0">
<tbody>
<tr>
</tr>
<tr>
<td class="td_first">Incident #: </td>
<td class="bold_detail">97011834</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Severity: </td>
<td>Critical</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Correlation: </td>
<td>No</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Status: </td>
<td>New</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">PreviousStatus: </td>
<td>-</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Reference #: </td>
<td></td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Assigned To: </td>
<td>AES Corporation</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Created: </td>
<td>3/9/2017 6:08:46 PM (GMT)</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Category: </td>
<td>Malicious Code (<b>46 incident(s) </b>in the past 30 days) </td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Classification: </td>
<td>Symantec Endpoint Reported Infection</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Description: </td>
<td class="Blockquote">This incident is a real-time notification of an infected host detected on your monitored network. This infection was identified by analyzing your Symantec Antivirus or Endpoint Protection log data for indications of an uncorrected threat
detected on a monitored host. <br>
<br>
When malware and other types of threats are detected by Antivirus or Endpoint Security, the application attempts to remove or quarantine the infected files. At times, this process cannot be completed successfully which leaves the host infected. This incident
represents a case where the threat detected was not successfully removed or quarantined from your host.<br>
<br>
A malware infected host residing on your protected network poses a risk to your organization. Many types of malware are multi-functional and have network propagation, remote control, data theft and various other capabilities. Additionally, security risks such
as spyware and adware introduce unwanted and potentially dangerous code into your organization. Many variants have the capability to download updated code to extend functionality and can cause the loss of host availability due to unauthorized system resource
modifications. <br>
</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">Analyst assessment: </td>
<td>The host identified as the source IP address in this incident has been infected with a threat that could not be corrected by your endpoint antivirus (AV) application. The SOC recommends triaging this host for malware infection.<br>
<br>
The AV threats listed on the host below were identified by the SOC as uncorrected:
<br>
- Trojan.Gen.2 on CHAN20-E6330PR - this threat has been observed on this host once in the past 7 days.<br>
<br>
Symantec's Security Response site can be used to access detailed write-ups including removal instructions for the threat identified above. Simply search for the threat using the link show below to access additional information:<br>
<br>
- Symantec Security Response<br>
http://www.symantec.com/security_response/<br>
<br>
AV system scans are sometimes insufficient to remediate malware infections. Please see Symantecs process for responding to active threats on a network:<br>
<br>
- Best Practices for Troubleshooting Viruses on a Network<br>
http://www.symantec.com/business/support/index?page=content&id=TECH122466<br>
<br>
Symantec Power Eraser (SPE) is the latest Symantec Recovery tool. The tool is aimed at the detection and clean-up of "zero-day" threats as well as other threats which may have infected a system and are difficult to remediate.
<br>
<br>
- How to run Symantec Power Eraser with the SymDiag utility<br>
https://support.symantec.com/en_US/article.TECH203683.html<br>
<br>
Please visit the SII web portal for a list of all currently infected hosts requiring remediation. This information can be found in the Reports section under the Managed Endpoint Infections Report.<br>
<br>
Questions or requests for further assistance related to this incident can be directed to the SOCs Analysis team.
</td>
</tr>
<tr>
<td class="td_first" nowrap="true" valign="top">LatestActivity: </td>
<td>CustomerSeverity :: Critical</td>
</tr>
<tr>
<td colspan="2"><br>
<a href="https://mss.symantec.com/PortalNextGen/Home/IncidentsDetails?IncidentId=97011834&CreatedDate=03/09/2017%2018:08:48.793">View Full Incident Details >>
</a></td>
</tr>
</tbody>
</table>
<br>
<br>
<span class="Title">SOURCE DETAILS</span>
<hr class="hrStandard" size="1">
<table>
<tbody>
<tr>
<td class="td_first">Source IP: </td>
<td><a href="https://mss.symantec.com/PortalNextGen/Home/Ipdetails?ip=10.249.174.167">10.249.174.167</a> (<b>1 incident(s)
</b>in the past 30 days) </td>
</tr>
<tr>
<td class="td_first">Country: </td>
<td>Reserved</td>
</tr>
<tr>
<td class="td_first">Organization(s): </td>
<td><i>No Organizations Found.</i><br>
</td>
</tr>
<tr>
<td colspan="2"><br>
</td>
</tr>
</tbody>
</table>
<br>
<span class="Title">DESTINATION DETAILS</span>
<hr class="hrStandard" size="1">
<table>
<tbody>
<tr>
<td nowrap="true" class="td_first">Organization(s): </td>
<td><i>No Organizations Found.</i></td>
</tr>
<tr>
<td colspan="2"><br>
</td>
</tr>
</tbody>
</table>
<br>
<span class="Title">ASSETS INVOLVED</span>
<hr class="hrStandard" size="1">
<table>
<tbody>
<tr>
<td>DMRP01-IS01-PR [AESCORP-MEP-112569] </td>
</tr>
<tr>
<td><br>
</td>
</tr>
</tbody>
</table>
<br>
<span class="Title">CORRELATED EVENTS</span>
<hr class="hrStandard" size="1">
<span class="Title">KEY EVENTS</span>
<table>
<tbody>
<tr>
<td nowrap="true" class="td_first">Event#: </td>
<td>13794917616</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Event Name: </td>
<td>Trojan.Gen.2</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Event Type: </td>
<td>Symantec AV Alert</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Created: </td>
<td>3/9/2017 6:08:12 PM (GMT)</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Source IP: </td>
<td class="ip_blue"><a href="https://mss.symantec.com/PortalNextGen/Home/Ipdetails?ip=10.249.174.167">10.249.174.167</a></td>
</tr>
<tr>
<td nowrap="true" class="td_first">Country: </td>
<td>Reserved</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Threat Name: </td>
<td></td>
</tr>
<tr>
<td nowrap="true" class="td_first">Malware MD5 Hashes: </td>
<td></td>
</tr>
<tr>
<td nowrap="true" class="td_first">Log Count: </td>
<td>2<br>
</td>
</tr>
<tr>
<td colspan="2" height="6"></td>
</tr>
<tr>
<td colspan="2" class="mep" align="left"><span class="Title">Source Host Details</span>
<table>
<tbody>
<tr>
<th class="shd1" align="left">Host Name</th>
<th class="shd1" align="left">Domain </th>
<th class="shd2" align="left">User(s)</th>
</tr>
<tr>
<td class="shd1" align="left">CHAN20-E6330PR</td>
<td class="shd1" align="left">aesmcac.local</td>
<td class="shd2" align="left">SYSTEM</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td height="12"></td>
</tr>
</tbody>
</table>
<br>
<span class="Title">OTHER EVENTS</span>
<table>
<tbody>
<tr>
<td nowrap="true" class="td_first">Event#: </td>
<td>13790181855</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Event Name: </td>
<td>Built-in rule</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Event Type: </td>
<td>Symantec Application/Device Control Alert</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Created: </td>
<td>3/9/2017 1:04:46 PM (GMT)</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Source IP: </td>
<td class="ip_blue"><a href="https://mss.symantec.com/PortalNextGen/Home/Ipdetails?ip=10.249.174.167">10.249.174.167</a></td>
</tr>
<tr>
<td nowrap="true" class="td_first">Country: </td>
<td>Reserved</td>
</tr>
<tr>
<td nowrap="true" class="td_first">Threat Name: </td>
<td></td>
</tr>
<tr>
<td nowrap="true" class="td_first">Malware MD5 Hashes: </td>
<td></td>
</tr>
<tr>
<td nowrap="true" class="td_first">Log Count: </td>
<td>1<br>
</td>
</tr>
<tr>
<td colspan="2" height="6"></td>
</tr>
<tr>
<td colspan="2" class="mep" align="left"><span class="Title">Source Host Details</span>
<table>
<tbody>
<tr>
<th class="shd1" align="left">Host Name</th>
<th class="shd1" align="left">Domain </th>
<th class="shd2" align="left">User(s)</th>
</tr>
<tr>
<td class="shd1" align="left">CHAN20-E6330PR</td>
<td class="shd1" align="left">aesmcac.local</td>
<td class="shd2" align="left">manpower.echu</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td height="12"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
<div class="lrm"><br>
<hr size="7">
<table>
<tbody>
<tr>
<td align="center" class="notice"><b>NOTICE OF CONFIDENTIALITY</b></td>
</tr>
<tr>
<td class="noticeDetail">This Email message and its attachments (if any) are intended solely for the use of the addressee hereof. In addition, this message and the attachments (if any) may contain information that is confidential, privileged and exempt from
disclosure under applicable law. If you are not the intended recipient of this message, you are prohibited from reading, disclosing, reproducing, distributing, disseminating or otherwise using this transmission. Delivery of this message to any person other
than the intended recipient is not intended to waive any right or privilege. If you have received this message in error, please promptly notify the sender by reply E-mail and immediately delete this message from your system.
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
</body>
</html>