Professional Documents
Culture Documents
Web Usage 4
Top 20 Most Active Users 4
Top 20 Most Visited Categories 4
Top 50 Most Visited Sites 5
Top 10 Online Users 5
Top 10 Categories 5
Top 50 Sites By Browsing Time 6
Top 20 Bandwidth Users 6
Top 20 Categories By Bandwidth 7
Top 50 Sites (and Category) by Bandwidth 7
Top 20 Most Blocked Users 8
Top 20 Most Blocked Categories 8
Top 50 Most Blocked Sites 8
Threats 9
Malware Detected 9
Malware Victims 9
Malware Source 9
Botnet Detected 9
Botnet Victims 9
Botnet C&C 9
Intrusions Detected 9
Intrusion Victims 10
Intrusion Sources 10
VPN Usage 11
VPN Traffic Usage Trend 11
Top SSL VPN Tunnel Users by Bandwidth 11
Top Site-to-Site IPsec Tunnels by Bandwidth 11
Top Dial-up IPsec Users by Bandwidth 11
Appendix A 13
Devices (1) 13
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 1 of 13
Bandwidth and Applications
Traffic Bandwidth
6GB
Sent
5GB
4GB
3GB
2GB
1GB
0
1GB
Received
2GB
3GB
4GB
5GB
6GB
0
0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
00
12
00
12
00
12
00
12
00
12
00
12
00
12
5
1
-2
-2
-2
-2
-2
-2
-2
-2
-2
-2
-3
-3
-0
-0
09
09
09
09
09
09
09
09
09
09
09
09
10
10
Number of Sessions
50K
Number of Sessions
40K
30K
20K
10K
0
0
0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
00
12
00
12
00
12
00
12
00
12
00
12
00
12
5
1
-2
-2
-2
-2
-2
-2
-2
-2
-2
-2
-3
-3
-0
-0
09
09
09
09
09
09
09
09
09
09
09
09
10
10
Top 20 Applications by Bandwidth
# Application Bandwidth Sent Received
1 HTTPS 26.40 GB
2 Akamai-CDN 12.17 GB
3 Edgio-CDN 9.35 GB
4 Microsoft-Web 7.57 GB
5 Google-Web 5.60 GB
6 Amazon-AWS 5.42 GB
7 Meta-Web 4.97 GB
8 POP3 4.96 GB
9 HTTP 4.29 GB
10 IMAPS 3.90 GB
11 Fastly-CDN 2.77 GB
12 Apple-Web 2.56 GB
13 POP3S 2.47 GB
14 Netflix-Web 2.11 GB
15 Amazon-Web 1.44 GB
16 Frontline-Frontline 1.27 GB
17 Cloudflare-CDN 1.20 GB
18 IMAP 623.84 MB
19 Microsoft-Outlook 439.55 MB
20 Zoom.us-Zoom.Meeting 439.33 MB
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 2 of 13
Top 20 Destination by Bandwidth
# Hostname(or IP) Bytes Sent Received
1 microsoft.com 20.65 GB
2 216.70.64.249 15.28 GB
3 starott.com 5.82 GB
4 138.255.98.135 5.18 GB
5 tiktokcdn.com 4.41 GB
6 mdstrm.com 4.14 GB
7 whatsapp.net 3.52 GB
8 aiv-cdn.net 3.35 GB
9 nflxvideo.net 2.89 GB
10 138.255.98.137 2.53 GB
11 138.255.98.134 2.17 GB
12 sfx.ms 1.96 GB
13 cloudfront.net 1.55 GB
14 gvt1.com 1.54 GB
15 fbcdn.net 1.50 GB
16 186.233.185.53 1.49 GB
17 apple.com 1.45 GB
18 akamaized.net 1.44 GB
19 191.98.131.208 1.42 GB
20 googleapis.com 1.37 GB
60
Active Users
45
30
15
0
0
0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
00
12
00
12
00
12
00
12
00
12
00
12
00
12
5
1
-2
-2
-2
-2
-2
-2
-2
-2
-2
-2
-3
-3
-0
-0
09
09
09
09
09
09
09
09
09
09
09
09
10
10
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 3 of 13
Web Usage
Top 20 Most Active Users
# User (or IP) Hostname Requests
1 192.168.1.96 192.168.1.96 249,599
2 192.168.1.109 192.168.1.109 31,492
3 192.168.1.71 192.168.1.71 20,822
4 192.168.1.73 192.168.1.73 18,813
5 192.168.1.234 192.168.1.234 17,623
6 192.168.1.67 192.168.1.67 16,249
7 192.168.1.85 192.168.1.85 14,069
8 192.168.1.173 192.168.1.173 13,561
9 192.168.1.63 192.168.1.63 13,426
10 192.168.1.56 192.168.1.56 13,205
11 192.168.1.106 192.168.1.106 13,121
12 192.168.1.54 192.168.1.54 12,438
13 192.168.1.99 192.168.1.99 11,550
14 192.168.1.153 192.168.1.153 11,541
15 192.168.1.66 192.168.1.66 11,463
16 192.168.1.8 192.168.1.8 11,441
17 192.168.1.83 192.168.1.83 11,438
18 192.168.1.72 192.168.1.72 11,405
19 192.168.1.82 192.168.1.82 11,180
20 192.168.1.101 192.168.1.101 11,089
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 4 of 13
Top 50 Most Visited Sites
# Website Category Requests
1 client.wns.windows.com Information Technology 250,948
2 4.tlu.dl.delivery.mp.microsoft.com Information Technology 19,969
Top 10 Categories
# Category Browsing Time(hh:mm:ss)
1 Information Technology 151:18:49
2 Information and Computer Security 65:23:57
3 Search Engines and Portals 63:58:35
4 Web-based Email 57:44:41
5 Instant Messaging 50:50:19
6 Social Networking 42:34:03
7 Web-based Applications 36:49:52
8 Business 35:55:56
9 Web Analytics 33:33:13
10 Web Chat 28:48:42
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 5 of 13
Top 50 Sites By Browsing Time
# Sites Category Browsing Time(hh:mm:ss)
1 dc1.ksn.kaspersky-labs.com Information Technology 116:47:23
2 threat.api.mcafee.com Information Technology 107:28:39
3 dc1-st.ksn.kaspersky-labs.com Information Technology 84:29:48
4 client.wns.windows.com Information Technology 78:13:12
5 dc1-file.ksn.kaspersky-labs.com Information Technology 72:00:47
6 mail.google.com Web-based Email 56:44:50
7 self.events.data.microsoft.com Information Technology 55:06:17
8 array807.prod.do.dsp.mp.microsoft.c Information Technology 53:04:32
om
9 teams.events.data.microsoft.com Information Technology 38:50:44
10 edge.microsoft.com Information Technology 38:45:19
11 officeclient.microsoft.com Information Technology 38:20:30
12 ctldl.windowsupdate.com Information Technology 35:36:03
13 analytics.apis.mcafee.com Information Technology 35:11:45
14 kv801.prod.do.dsp.mp.microsoft.com Information Technology 32:42:03
15 nexusrules.officeapps.live.com Web-based Applications 29:07:32
16 web.whatsapp.com Web Chat 28:37:10
17 sadownload.mcafee.com Information and Computer 28:27:03
Security
18 ocsp.digicert.com Information and Computer 27:31:34
Security
19 dit.whatsapp.net Instant Messaging 26:13:34
20 assets.msn.com Search Engines and Portals 25:07:06
21 disc801.prod.do.dsp.mp.microsoft.co Information Technology 25:07:03
m
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 6 of 13
Top 20 Categories By Bandwidth
# Category Bytes
1 Information Technology 33.18 GB
2 Streaming Media and Download 9.89 GB
3 Content Servers 7.31 GB
4 Social Networking 6.99 GB
5 Travel 5.94 GB
6 Instant Messaging 3.64 GB
7 File Sharing and Storage 3.00 GB
8 Finance and Banking 1.84 GB
9 Search Engines and Portals 1.50 GB
10 Business 1.09 GB
11 Games 710.15 MB
12 Shopping 669.92 MB
13 Online Meeting 643.58 MB
14 Advertising 599.09 MB
15 Government and Legal Organizations 371.67 MB
16 Information and Computer Security 366.43 MB
17 Entertainment 248.74 MB
18 Web-based Email 242.42 MB
19 Education 233.37 MB
20 Web-based Applications 233.02 MB
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 7 of 13
Top 20 Most Blocked Users
# User (or IP) Hostname Requests
1 192.168.1.77 192.168.1.77 906
2 192.168.1.109 192.168.1.109 295
3 192.168.1.108 192.168.1.108 269
4 192.168.1.61 192.168.1.61 258
5 192.168.1.99 192.168.1.99 256
6 192.168.1.96 192.168.1.96 219
7 192.168.1.105 192.168.1.105 167
8 192.168.1.56 192.168.1.56 161
9 192.168.1.91 192.168.1.91 152
10 192.168.1.163 192.168.1.163 146
11 192.168.1.82 192.168.1.82 109
12 192.168.1.101 192.168.1.101 102
13 192.168.1.107 192.168.1.107 80
14 192.168.1.102 192.168.1.102 70
15 192.168.1.57 192.168.1.57 62
16 192.168.1.173 192.168.1.173 50
17 192.168.1.75 192.168.1.75 50
18 192.168.1.90 192.168.1.90 38
19 192.168.1.110 192.168.1.110 36
20 192.168.1.97 192.168.1.97 34
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 8 of 13
Threats
Malware Detected
Malware Victims
Malware Source
Botnet Detected
# Botnet Name Counts
1 Mirai.Botnet 4
2 SystemBC.Botnet 3
3 Gh0st.Rat.Botnet 2
4 Bladabindi.Botnet 1
Botnet Victims
# Victim Name (or IP) Counts
1 1.23.114.2 3
2 66.240.205.34 2
3 159.203.80.159 1
4 164.52.36.213 1
5 206.189.228.37 1
6 159.65.15.219 1
7 103.83.144.161 1
Botnet C&C
# C&C IP Hostname Counts
1 192.168.1.7 4
2 192.168.1.7 127[dot]0[dot]0[dot]1 3
3 192.168.1.7 190[dot]12[dot]86[dot]20 3
Intrusions Detected
# Attack Name Severity CVE-ID Counts
1 Backdoor.DoublePulsar Critical 130
2 PHPUnit.Eval-stdin.PHP.Re Critical CVE-2017-9841 13
mote.Code.Execution
3 Apache.Log4j.Error.Log.Re Critical CVE-2021-4104,CVE-2021 6
mote.Code.Execution -44228,CVE-2021-45046
4 MS.Windows.HTTP.sys.Req Critical CVE-2015-1635 3
uest.Handling.Remote.Code.Ex
ecution
5 Gh0st.Rat.Botnet Critical 2
6 Bladabindi.Botnet Critical 1
7 D-Link.DSL-2750B.CLI.OS.C Critical CVE-2016-20017 1
ommand.Injection
8 MS.Windows.HTTP.sys.UlpP Critical CVE-2021-31166 1
arseAcceptEncoding.Use.After.
Free
9 Multiple.Routers.GPON.for High 36
mLogin.Remote.Command.Inje
ction
10 Generic.XXE.Detection High CVE-2012-3363,CVE-2013 6
-4295,CVE-2013-5015,CV
E-2014-3490,CVE-2016-9
563,CVE-2018-8527,CVE-
2018-8532,CVE-2018-853
3,CVE-2019-0537,CVE-20
19-0948,CVE-2019-2647,
CVE-2019-2648,CVE-2019
-2649,CVE-2019-2650,CV
E-2020-0765,CVE-2021-2
400,CVE-2022-1018,CVE-
2018-13415,CVE-2018-13
416,CVE-2018-13417,CVE
-2018-15444,CVE-2018-1
8471,CVE-2019-17554,CV
E-2019-18227,CVE-2019-
18227,CVE-2020-15418,C
VE-2020-15419,CVE-2020
-26981,CVE-2021-21658,
CVE-2021-21659,CVE-202
1-21672,CVE-2021-29447
,CVE-2021-31207,CVE-20
22-24463,CVE-2022-2821
9,CVE-2022-43473,CVE-2
022-45468,CVE-2022-462
86,CVE-2022-46300
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 9 of 13
Intrusion Victims
# Attack Victim Counts
1 192.168.1.7 46
Intrusion Sources
# Attack Source Counts
1 192.168.1.17 279
2 83.97.73.87 24
3 95.214.55.115 8
4 193.35.18.31 7
5 95.214.55.244 6
6 45.88.90.113 6
7 45.88.90.116 5
8 45.88.90.111 5
9 192.168.1.131 4
10 103.127.78.55 4
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 10 of 13
VPN Usage
VPN Traffic Usage Trend
1B
SSL
IPSEC
0
0
0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
00
12
00
12
00
12
00
12
00
12
00
12
00
12
5
1
-2
-2
-2
-2
-2
-2
-2
-2
-2
-2
-3
-3
-0
-0
09
09
09
09
09
09
09
09
09
09
09
09
10
10
Top SSL VPN Tunnel Users by Bandwidth
# User IP First Used Bytes Sent Received
1 soporteds 190.107.183.174 2023-09-28 15:03:44 13.93 MB
2 soporteds 38.25.15.115 2023-09-28 10:45:59 2.42 MB
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 11 of 13
Admin Login and System Events
Login Summary
Events by Severity
Events by Date
1
Critical
High
Medium
0
0
0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
:0
00
12
00
12
00
12
00
12
00
12
00
12
00
12
5
1
-2
-2
-2
-2
-2
-2
-2
-2
-2
-2
-3
-3
-0
-0
09
09
09
09
09
09
09
09
09
09
09
09
10
10
Critical Severity Events
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 12 of 13
Appendix A
Devices (1)
K-IS-BLADE10[ISA49092]
ISA49092 - Reporte Semanal - PC LINK S.A.C. (by cgutierrez) - FortiAnalyzer Host Name: FAZ-2000E-IS-KRUMDIECK page 13 of 13