FortiSIEM Discussions
nz
New Contributor

FortiSIEM - Traffic from x.x.x.x to Malware IP 192.143.59.12

Hi all,

I've got an incident based on traffic from an internal IP to Malware IP 192.143.59.12. FortiGuard is not showing anything regarding 192.143.59.12. Neither the Malware IP list under FortiSIEM -> Resources.

I know that Malware IP's are based on services such as Emerging Threat.

Why is FortiSIEM classifying  IP 192.143.59.12 as a malware?

 

Thank you,

Norberth

 

 

1 Solution
FSM_FTNT
Staff
Staff

Hi NZ,

 

192.143.59.12 is not if the FortiSIEM IOC feed. Is this the correct IP address?

View solution in original post

3 REPLIES 3
sioannou
Contributor

Hi Norberth, 

 

Can you provide the rule that triggered the incident. If it is not in the Threat Intelligence Resources then this is a weird behaviour. 

 

S

 

FSM_FTNT
Staff
Staff

Hi NZ,

 

192.143.59.12 is not if the FortiSIEM IOC feed. Is this the correct IP address?

nz
New Contributor

I've checked again the IP with the customer and it's 192.243.59.12, for which I can find an entry in the Malicious Ip list. 

Thank you.