imp.onesearch.org - Compromised Host Detection by IOC
Hi Folks:
Trying to understand what Alert and Hostname are and whether or not we need to whitelist this. Below are the details from one of our Firewalls:
Log ID
Type
utm
Sub Type
webfilter
Event Type
ftgd_blk
Level
warning
eventtime
1587743286
Policy ID
2
Session ID
11105149
Source IP
10.80.6.135
Source Port
59657
Source Interface
LAN
srcintfrole
lan
Destination Interface
wan1
dstintfrole
wan
Protocol
6
Service
HTTPS
Host Name
imp.onesearch.org
Profile
default
Action
blocked
Request Type
direct
URL
/
Sent
517
Received
0
Direction
outgoing
Message
URL belongs to a denied category in policy
Method
domain
Category
26
Category Description
Malicious Websites
Threat Score
60
Threat Level
high
When I performed a search on VirusTotal only Fortinet and Forcepoint marked that hostname as suspicious.
Log ID0316013056TypeutmSub TypewebfilterEvent Typeftgd_blkLevelwarningeventtime1587743286Policy ID2Session ID11105149Source IP10.80.6.135Source Port59657Source InterfaceLANsrcintfrolelanDestination IP34.232.56.142Destination Port443Destination Interfacewan1dstintfrolewanProtocol6ServiceHTTPSHost Nameimp.onesearch.orgProfiledefaultActionblockedRequest TypedirectURL/Sent517Received0DirectionoutgoingMessageURL belongs to a denied category in policyMethoddomainCategory26Category DescriptionMalicious WebsitesThreat Score60Threat Levelhigh
