Subject: Re: MPSWAN Firewall daily security report (2nd,3rd & 4th sep 2018)From: "RajeshPrasadKushwaha mpsedc" <rajeshk...@mpsedc.com>Date: Tue, 04 Sep 2018 11:47:25 +0530To: Siddhartha Rajbhatt <sraj...@mpsedc.com>,Pradeep Rathore <PRat...@netlink.com>,Mithlesh Belawat <MBel...@netlink.com>,"Rizwan Mohd. Khan" <RMK...@netlink.com>,Doordarshak Mishra <Doorda...@netlink.com>,Rakesh Manware <RMan...@netlink.com>, Shahab Ahmed <Sha...@netlink.com>,"mpswanh...@gmail.com" <mpswanh...@gmail.com>Cc: Ripudaman Bhadoria <pds...@mpsedc.com>,rambadkar <ramb...@mpsedc.com>,john rebeiro <johnr...@mpsedc.com>,Deepak Verma <deepa...@mpsedc.com>,Manoj Saxena <manojkum...@mpsedc.com>,khali...@mapit.gov.in,Yogendra Varma <yogend...@kpmg.com>,Robin Sharma <robin...@mpsedc.com>,Rohit Gupta <rohit...@mpsedc.com>,Jagdish Shrivas <jagd...@mpsedc.com>, Mahendra Kumar <m.k...@mpsedc.com>,Saurabh Dubey <saurabhk...@mpsedc.com>Dear Team,
Pls find the attached MPSWAN Fortigate firewall security reports (2nd sep 2018 , 3rd sep 2018 & 4th sep 2018 ).
Request you to go through the attachments and do the needful.
RegardsRajesh KushwahaBhopal (M.P)
On 09/01/18 11:22 AM, "RajeshPrasadKushwaha mpsedc" <rajeshk...@mpsedc.com> wrote:Dear Team,Pls find the attached MPSWAN Fortigate firewall security report (data range 30/08/2018 23:30 to 31/08/2018 23:29).As per the attached report:1.Top users consuming very high bandwidth:
- 10.115.139.34 (Total 335.7 GB used in 24 hrs)
- 10.124.131.116 (Total 275.7 GB used in 24 hrs)
- 10.124.50.214 (Total 169.6 GB used in 24 hrs)
2.Top Intrusion source & victim user systems:
- 10.124.61.131
- 10.115.84.132
- 10.124.143.198
- 10.124.24.158
3.Top Botnet (C&C attack) user systems:
- 10.125.53.198
- 10.125.73.109
- 10.125.37.174
- 10.125.7.165
Recommendation: Kindly inform the users and request to follow the MPSWAN security advisory (http://mapit.gov.in/cyberswachta.aspx)
RegardsRajesh KushwahaBhopal (M.P)
----
Top botnet10.125.77.202 PaleraLSK10.124.48.145 KundamJanpad10.124.96.211 DHQ_MorenaRCBCTop Users by Request10.124.192.144PansemalSDM Office, Nirvachan10.125.10.202 DHQ_UmariaRCBC10.124.104.216DHQ_SehoreMahila Polytechnic10.125.158.230DHQ DindoriRCBC10.125.169.199BHQ JaithariPanchayat & Rural Development Department10.124.3.154 BhopalBhopal RSK10.115.137.34 BhopalPWDTop Bandwidth Consuming user10.115.139.34 BhopalJail Mukhyalaya10.115.139.38 BhopalJail Mukhyalaya10.124.4.75 BSNL NMSBSNL NMS
Dear Sir,
Please refer trail mail and inform to user for necessary action.
Thanks & Regards
Mithlesh Belawat, Operation Manager (MPSWAN), EMS| Netlink Software Pvt. Ltd |Your
link to Immediate Business Results |India|
Mobile No.7773004526
MPSWAN Helpdesk No :0755-2518411,12
***WARNING: This email originated from outside of the organization. If you do not recognize the sender do not open attachments or click any links contained in this email unless and know contents are safe.***
___________________________________________________________________
Top Bandwidth Consuming | ||
10.115.139.34 | Jail Mukhyalaya | ,dhqcont...@mp.gov.in |
10.115.139.38, | Jail Mukhyalaya | ,dhqcont...@mp.gov.in |
Top Users By Request | ||
10.124.192.144 | SDM Office, Nirvachan | sdmp...@gmail.com |
10.125.10.202 | RCBC,umaria | ceoz...@mp.gov.in |
10.124.104.216 | Mahila Polytechnic,sehore | prinwp...@mp.gov.in |
10.125.158.230 | RCBC ,dindori | rbunk...@gmail.com |
10.125.169.199 | Panchayat & Rural Development Department,jaithari | manrega....@gmail.com |
10.124.3.154 | Bhopal RSK | kushwah...@gmail.com |
Top botnet(command&control)attack | ||
10.124.90.208 | LSK,dabra | anan...@gmail.com |
10.124.171.158 | Janpad,Sondawa | ceojp....@gmail.com |
10.125.77.202 | LSK,Palera | Lokesev...@gmail.com |
10.124.48.145 | Janpad,Kundam | anil977...@gmail.com |
10.124.96.211 | RCBC,Morena | goyalgo...@gmail.com |
Top intrusion source & victim system/users | ||
10.124.61.131 | LSK,Pandhurna | pravindo...@gmail.com |
10.125.83.186 | Tehsil,Bahoriband | naveentr...@gmail.com |
10.124.91.203 | VCR,Bhitarwar | hssbhi...@gmail.com |
10.124.102.199 | Janpad,Kailaras |
10.125.77.202 | LSK,Palera | Lokesev...@gmail.com |
10.124.48.145 | Janpad,Kundam | anil977...@gmail.com |
10.124.192.144 | SDM Office, Pansemal | sdmp...@gmail.com |
10.125.10.202 | RCBC,umaria | ceoz...@mp.gov.in |
10.124.104.216 | Mahila Polytechnic,sehore | prinwp...@mp.gov.in |
10.125.158.230 | RCBC ,dindori | rbunk...@gmail.com |
Dear Sir,
We are regularly informed to concern for necessary action to prevent such types of attacks.
Thanks & Regards
Mithlesh Belawat, Operation Manager (MPSWAN), EMS| Netlink Software Pvt. Ltd |Your
link to Immediate Business Results |India|
Mobile No.7773004526
MPSWAN Helpdesk No :0755-2518411,12
From: ramb...@mpsedc.com [mailto:ramb...@mpsedc.com]
Sent: Saturday, October 06, 2018 5:10 PM
To: RajeshPrasadKushwaha mpsedc; Jagdish Shrivas; Deepak Verma; Robin Sharma; Rohit Gupta; Saurabh Dubey; Mahendra Kumar; degmhos...@gmail.com; egovma...@googlegroups.com; Aegovm...@google.com; Pradeep Rathore; Mithlesh Belawat
Cc: Ripudaman Bhadoria; john rebeiro; Manoj Saxena; khali...@mapit.gov.in; Yogendra Varma
Subject: Re: MPSWAN security report
Dear SWAN Team
***WARNING: This email originated from outside of the organization. If you do not recognize the sender do not open attachments or click any links contained in this email unless and know contents are safe.***
___________________________________________________________________
10.124.90.208 LSK,dabra anan...@gmail.com
10.124.91.203 VCR,Bhitarwar hssbhi...@gmail.com