Skip to main content
beilerman
New Member
October 21, 2016
Question

botnet to 204.79.197.200 (Office 365)

  • October 21, 2016
  • 2 replies
  • 7175 views

Hi,

 

I'm seeing a few of the following messages in my security logs:

 

Message meets Alert condition

File Block Detected:  Protocol:  Source IP: 192.168.0.118 Destination IP: 204.79.197.200 Email Address From:  Email Address To:

date=2016-10-21 time=10:37:30 devname=FG100D3G14811908 devid=FG100D3G14811908 logid=0202009248 type=utm subtype=virus eventtype=botnet level=warning vd="root" msg="Botnet C&C Communication." action=blocked sessionid=590954314 srcip=192.168.0.118 dstip=204.79.197.200 srcport=50318 dstport=80 srcintf="lan" dstintf="wan2" proto=6 direction=outgoing quarskip=No-skip virus="HW20161020" dtype="ip-reputation" ref="http://www.fortinet.com/be?bid=7630162" virusid=7630162 profile="default" user="" analyticssubmit=false crscore=50 crlevel=critical  

 

Is there any additional information on this?  The IP seems to be Microsoft edge services for office365 and bing.  

 

Seems like a false positive but wanted to see if anybody else has seen this one and has some insight.

 

I look forward to your reply.

 

Brandon

    2 replies

    tclark
    New Member
    October 21, 2016

    See this post. It has to do with the DDoS on Dyn.

     

    [link]https://forum.fortinet.com/FindPost/142420[/link]

    beilerman
    beilermanAuthor
    New Member
    October 21, 2016

    Perfect... thank you!

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.