You would have to look up those IPs to see what they are. Maybe from your ISP?
In any case, SEP is doing its job of blocking these attempted attacks.
Original Message:
Sent: May 06, 2024 04:39 PM
From: nambi_
Subject: Help I can't removed this Coinminer Activity 2 attack blocked
no these IP's which are constantly changing I have no idea were they come form as we are on a 192.168.1 network here.
152.32.205.193
101.36.108.175
101.36.97.74
incoming from WAN?
Original Message:
Sent: May 06, 2024 04:26 PM
From: nambi_
Subject: Help I can't removed this Coinminer Activity 2 attack blocked
Here is a snapshot I dont' see incoming our outgoing but I'm assuming it's outgoing from my 192.168.1.4

Original Message:
Sent: May 06, 2024 01:02 PM
From: John Owens
Subject: Help I can't removed this Coinminer Activity 2 attack blocked
The Intrusion Prevention technology detects network traffic to or from this device that matches the attack signature ID [SID: 30482].
If you look at the full log you should be able to tell if it is Inbound or Outbound traffic.
------------------------------
John Owens
Strategic Support Engineer | Enterprise Security Group
Broadcom Software
Original Message:
Sent: May 06, 2024 12:58 PM
From: nambi_
Subject: Help I can't removed this Coinminer Activity 2 attack blocked
Ok John but based on what you mentioned before is this warning on the machine which the client log / security is showing this?
Original Message:
Sent: May 06, 2024 10:05 AM
From: John Owens
Subject: Help I can't removed this Coinminer Activity 2 attack blocked
Please open a Support Case to assist you with this one.
------------------------------
John Owens
Strategic Support Engineer | Enterprise Security Group
Broadcom Software
Original Message:
Sent: May 06, 2024 06:54 AM
From: nambi_
Subject: Help I can't removed this Coinminer Activity 2 attack blocked
Can you please elaborate. This is the ONLY server on this same network showing this. Users connected via citirx are seeing this Symantec popup via their terminal services.
Upon reading about this, I'm led to believe something is on this server causing this, but it's difficult to detect and remove.
No other computers on the network from what I can see are detecting this. I can only see this in the client logs.
Original Message:
Sent: May 05, 2024 07:40 PM
From: John Owens
Subject: Help I can't removed this Coinminer Activity 2 attack blocked
This is a Network traffic detection by Intrusion Prevention. It's not something on the physical server.
------------------------------
John Owens
Strategic Support Engineer | Enterprise Security Group
Broadcom Software
Original Message:
Sent: May 05, 2024 08:41 AM
From: nambi_
Subject: Help I can't removed this Coinminer Activity 2 attack blocked
[SID: 30482] System Infected: Coinminer Activity 2 attack blocked. Traffic has been blocked for this application: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
Intensive Protection level: N/A
I reverted from a backup from 2022 spent almost 20 hours getting this server back online, and today I see this again. I'm so frustrated with this.
We have had endpoint for over 10 years. My scans will not detect this, but this constantly shows up in the client logs this is the only way i detect it, and sometime a pop up when this is blocked This does not show up in scans. I highly doubt this was in my 2022 backup.