Hi Parunyu/Varunee,
We are from SOC team managing Security Operations for ZIM environment.
We have been observing suspicious network traffic being detected by Checkpoint advanced URL Filtering blade and require your assistance to trace the end machine.
Source IP: 10.95.1.151
Destination IP: 58.97.45.121
Destination Port: 80
Firewall IP: 61.91.84.50(BGKfwm, Asia)
This is a browser based activity which is being flagged as ‘spam’ traffic, getting blocked and redirected.
We observed more than 87000 connections from this IP in past 7 days which were blocked by the Checkpoint considering suspicious attempts.
To further investigate on this issue, we need coordinate with Bangkok local IT Team and user as well.
Request you to confirm if you are the person appropriate person who can assist us in this case.
If yes, please provide us below details:
Request you to let us know details about the source IP.
Is it any end machine or a server?
Can we get the hostname and user details to further investigate?