Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
2013-01-27 14:52:36,High,An intrusion attempt by "user name" was blocked.,Blocked,No Action Required,"Malicious Site: Malicious Web Site, Domain, or URL 2",No Action Required,No Action Required,"user name (192.168.1.7, 50354)","wsdl5.yunpan.cn/share.php?method=Share.download&fhash=7a58274d9a01e87b22bd80cc895844e6dffdec2b&xqid=31466288&fname=qqpinyin_setup_1.exe&fsize=26900738&nid=13593000182951780&cqid=654c4f4569b2ed2530ac1631d66caaa6&st=452e8802fbd70fba9a7961fb800cff24&e=1359499957","wsdl5.yunpan.cn (202.102.99.246, 80)",192.168.1.7 (192.168.1.7),"TCP, Port 50354"
Network traffic from <b>wsdl5.yunpan.cn/share.php?method=Share.download&fhash=7a58274d9a01e87b22bd80cc895844e6dffdec2b&xqid=31466288&fname=qqpinyin_setup_1.exe&fsize=26900738&nid=13593000182951780&cqid=654c4f4569b2ed2530ac1631d66caaa6&st=452e8802fbd70fba9a7961fb800cff24&e=1359499957</b> matches the signature of a known attack. The attack was resulted from \DEVICE\HARDDISKVOLUME2\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE. To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>.
|