relatório semanal u&m - investlinux –...

25
Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço em Disco OK Dmesg OK Logs OK Dat Anti-Vírus OK Top - Memória / Processos / Carga OK Processos OK Portas Tcp Udp Abertas OK MRTG - Tráfego OK MRTG - Processador OK Ipaudit Diário OK Ipaudit Semanal OK Squid Reports - TopSites OK Squid Reports - TopUsers OK Nagios - Disponibilidade HTTP 92,42%* Nagios - Disponibilidade SMTP 56,60%** *Serviço indisponível entre 13/04/2011 19:30h e 14/04/2011 07:58h **Serviço indisponível entre 13/04/2011 19:30h e 14/04/2011 07:58h e entre 15/04/2011 20:47h e 18/04/2011 11:15h

Upload: others

Post on 10-Jul-2020

10 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Relatório Semanal U&M - InvestLinux – 18/04/2011

Uptime / Last OK

Espaço em Disco OK

Dmesg OK

Logs OK

Dat Anti-Vírus OK

Top - Memória / Processos / Carga OK

Processos OK

Portas Tcp Udp Abertas OK

MRTG - Tráfego OK

MRTG - Processador OK

Ipaudit Diário OK

Ipaudit Semanal OK

Squid Reports - TopSites OK

Squid Reports - TopUsers OK

Nagios - Disponibilidade HTTP 92,42%*

Nagios - Disponibilidade SMTP 56,60%**

*Serviço indisponível entre 13/04/2011 19:30h e 14/04/2011 07:58h**Serviço indisponível entre 13/04/2011 19:30h e 14/04/2011 07:58h e entre 15/04/2011 20:47h e 18/04/2011 11:15h

Page 2: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Uptime / LastUptime - Tempo Online do ServidorLast - Conexões remotas

[root@uem-gw]# uptime 11:04:55 up 25 min, 2 users, load average: 1.54, 1.08, 2.34

[root@uem-gw]# last | sort -k 3 | morecollect ftpd16657 123.30.72.108 Thu Apr 7 08:30 - 08:40 (00:09) collect ftpd16658 123.30.72.108 Thu Apr 7 08:30 - 08:40 (00:10) collect ftpd21645 123.30.72.108 Thu Apr 7 10:06 - 10:16 (00:10) collect ftpd28358 125-215-156-125. Fri Apr 8 14:58 - 15:02 (00:03) collect ftpd28359 125-215-156-125. Fri Apr 8 14:58 - 15:02 (00:03) collect ftpd32363 125-215-156-125. Fri Apr 8 15:45 - 15:55 (00:09) collect ftpd32364 125-215-156-125. Fri Apr 8 15:45 - 15:55 (00:10) collect ftpd3676 125-215-156-125. Fri Apr 8 16:29 - 16:30 (00:00) vpnuem ppp0 189.118.100.71 Tue Apr 12 10:45 - 17:25 (06:39) vpnuem ppp0 189.118.118.75 Mon Apr 11 11:47 - 19:10 (07:22) vpnuem ppp1 189.118.244.39 Tue Apr 12 15:07 - 18:00 (02:52) vpnuem ppp0 189.118.98.172 Tue Apr 12 17:35 - 17:49 (00:13) vpnuem ppp0 189.119.202.5 Wed Apr 13 09:12 - 11:08 (01:56) vpnuem ppp0 189.13.41.27 Fri Apr 1 16:46 - 17:41 (00:54) vpnuem ppp0 189.17.213.195 Sun Apr 10 18:24 - 20:12 (01:48) vpnuem ppp1 189.17.213.195 Sun Apr 10 19:02 - 20:12 (01:09) vpnuem ppp2 189.17.213.195 Sun Apr 10 19:04 - 20:09 (01:05) vpnuem ppp0 189.17.213.195 Sun Apr 10 20:17 - 20:28 (00:11) vpnuem ppp0 189.17.213.195 Sun Apr 10 20:31 - 20:50 (00:19) vpnuem ppp0 189.17.213.195 Sun Apr 17 14:20 - 14:54 (00:33) vpnuem ppp1 189.17.213.195 Sun Apr 17 14:32 - 14:55 (00:22) uem ftpd17406 189.3.236.211 Fri Apr 1 09:34 - 09:43 (00:08) uem ftpd17405 189.3.236.211 Fri Apr 1 09:34 - 09:44 (00:09) uem ftpd17454 189.3.236.211 Fri Apr 1 09:36 - 09:46 (00:10) uem ftpd30330 189.3.236.211 Fri Apr 15 11:50 - 11:52 (00:01) uem ftpd30329 189.3.236.211 Fri Apr 15 11:50 - 12:00 (00:10) uem ftpd25978 189.3.236.211 Mon Apr 11 09:07 - 09:09 (00:01) uem ftpd25977 189.3.236.211 Mon Apr 11 09:07 - 09:17 (00:09) uem ftpd25993 189.3.236.211 Mon Apr 11 09:08 - 09:08 (00:00) uem ftpd25994 189.3.236.211 Mon Apr 11 09:08 - 09:18 (00:10) uem ftpd26010 189.3.236.211 Mon Apr 11 09:09 - 09:09 (00:00) uem ftpd26011 189.3.236.211 Mon Apr 11 09:09 - 09:19 (00:10) uem ftpd463 189.3.236.211 Mon Apr 11 19:16 - 19:26 (00:10) uem ftpd464 189.3.236.211 Mon Apr 11 19:16 - 19:26 (00:10) uem ftpd2806 189.3.236.211 Mon Apr 11 19:30 - 19:36 (00:06) uem ftpd1836 189.3.236.211 Sat Apr 2 10:24 - 10:34 (00:10) uem ftpd2452 189.3.236.211 Sat Apr 2 10:24 - 10:39 (00:14) uem ftpd3577 189.3.236.211 Sat Apr 2 10:37 - 10:47 (00:10) uem ftpd25029 189.3.236.211 Sat Apr 2 15:26 - 15:36 (00:09) uem ftpd25030 189.3.236.211 Sat Apr 2 15:26 - 15:37 (00:10) uem ftpd29347 189.3.236.211 Sat Apr 2 16:29 - 16:39 (00:10) uem ftpd29348 189.3.236.211 Sat Apr 2 16:29 - 16:39 (00:10)

Espaço em Disco[root@uem-gw]# df -hSist. Arq. Tam Usad Disp Uso% Montado em/dev/sda3 38G 22G 15G 60% /varrun 1014M 264K 1014M 1% /var/runvarlock 1014M 4,0K 1014M 1% /var/lockudev 1014M 52K 1014M 1% /devdevshm 1014M 0 1014M 0% /dev/shm/dev/sdb1 50G 16G 32G 33% /backup/dev/sda1 471M 140M 308M 32% /boot//192.168.0.105/Pessoal 20G 5,8G 15G 29% /ftp/Pessoal//192.168.0.105/Public 200G 181G 20G 91% /ftp/Public//192.168.0.105/Restrito 200G 181G 20G 91% /home/Restrito//192.168.0.100/CorporeRM 47G 18G 30G 37% /home/ponto//192.168.0.105/BKP-linux 78G 63G 16G 81% /backup-remoto

Page 3: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Dmesg

Dmesg – Alertas de Console (Eventuais Erros de Disco, Rede, Hardware em geral)- Sem informações relevantes -

Logs

Verificação superficial de logs do sistema: ( syslog(tmsys) / secure(tms) / squid(tmsq) )

Dat Anti-Vírus

[root@uem-gw]# freshclamClamAV update process started at Mon Apr 18 11:07:00 2011WARNING: Your ClamAV installation is OUTDATED!WARNING: Local version: 0.96.5 Recommended version: 0.97DON'T PANIC! Read http://www.clamav.net/support/faqmain.cld is up to date (version: 53, sigs: 846214, f-level: 53, builder: sven)daily.cld is up to date (version: 12994, sigs: 99065, f-level: 60, builder: ccordes)bytecode.cld is up to date (version: 143, sigs: 40, f-level: 60, builder: edwin)

Semana Anterior:ClamAV update process started at Mon Apr 11 10:49:58 2011 WARNING: Your ClamAV installation is OUTDATED! WARNING: Local version: 0.96.5 Recommended version: 0.97 DON'T PANIC! Read http://www.clamav.net/support/faq main.cld is up to date (version: 53, sigs: 846214, f-level: 53, builder: sven) daily.cld is up to date (version: 12966, sigs: 96921, f-level: 60, builder: guitar) bytecode.cld is up to date (version: 142, sigs: 40, f-level: 60, builder: acab)

Top - Memória / Processos / Carga- Sem informações relevantes -

Processos- Sem informações relevantes -

Portas Tcp Udp Abertas

[root@uem-gw]# netstat -ap | grep LISTEN | grep -v STREAMtcp 0 0 localhost:60000 *:* LISTEN 6652/postgrey.pid -tcp 0 0 192.168.0.1:5666 *:* LISTEN 7024/nrpe tcp 0 0 *:rsync *:* LISTEN 7206/rsync tcp 0 0 localhost:mysql *:* LISTEN 6568/mysqld tcp 0 0 *:webmin *:* LISTEN 8616/perl tcp 0 0 *:81 *:* LISTEN 7507/apache2 tcp 0 0 *:ftp *:* LISTEN 7355/proftpd: (accetcp 0 0 192.168.1.1:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.12:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.50:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.11:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.10:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.9:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.8:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.7:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.6:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.4:domain *:* LISTEN 6187/named tcp 0 0 200.243.57.3:domain *:* LISTEN 6187/named tcp 0 0 correio.uem.com.:domain *:* LISTEN 6187/named tcp 0 0 uemnotes.uem.com:domain *:* LISTEN 6187/named tcp 0 0 192.168.0.1:domain *:* LISTEN 6187/named tcp 0 0 localhost:domain *:* LISTEN 6187/named tcp 0 0 *:ssh *:* LISTEN 6465/sshd tcp 0 0 *:3128 *:* LISTEN 7659/(squid) tcp 0 0 localhost:953 *:* LISTEN 6187/named tcp 0 0 *:1723 *:* LISTEN 7193/pptpd tcp6 0 0 [::]:rsync [::]:* LISTEN 7206/rsync tcp6 0 0 [::]:domain [::]:* LISTEN 6187/named tcp6 0 0 [::]:ssh [::]:* LISTEN 6465/sshd tcp6 0 0 [::]:3000 [::]:* LISTEN 7047/ntop tcp6 0 0 ip6-localhost:953 [::]:* LISTEN 6187/named Obs: Comando mostra na quarta coluna, preferencialmente, o nome do serviço após o caracter “:”.

Page 4: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

root@uem-gw:~# netstat -nap | grep LISTEN | grep -v STREAMtcp 0 0 127.0.0.1:60000 0.0.0.0:* LISTEN 6652/postgrey.pid -tcp 0 0 192.168.0.1:5666 0.0.0.0:* LISTEN 7024/nrpe tcp 0 0 0.0.0.0:873 0.0.0.0:* LISTEN 7206/rsync tcp 0 0 127.0.0.1:3306 0.0.0.0:* LISTEN 6568/mysqld tcp 0 0 0.0.0.0:10000 0.0.0.0:* LISTEN 8616/perl tcp 0 0 0.0.0.0:81 0.0.0.0:* LISTEN 7507/apache2 tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN 7355/proftpd: (accetcp 0 0 192.168.1.1:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.12:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.50:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.11:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.10:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.9:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.8:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.7:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.6:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.4:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.3:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.2:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 200.243.57.5:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 192.168.0.1:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 127.0.0.1:53 0.0.0.0:* LISTEN 6187/named tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 6465/sshd tcp 0 0 0.0.0.0:3128 0.0.0.0:* LISTEN 7659/(squid) tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN 7186/master tcp 0 0 127.0.0.1:953 0.0.0.0:* LISTEN 6187/named tcp 0 0 0.0.0.0:1723 0.0.0.0:* LISTEN 7193/pptpd tcp6 0 0 :::873 :::* LISTEN 7206/rsync tcp6 0 0 :::53 :::* LISTEN 6187/named tcp6 0 0 :::22 :::* LISTEN 6465/sshd tcp6 0 0 :::3000 :::* LISTEN 7047/ntop tcp6 0 0 ::1:953 :::* LISTEN 6187/named Obs: Comando mostra na quarta coluna a porta do serviço após o caracter “:”.

Page 5: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

MRTG - Tráfego*

Internet – eth1

Roteador Embratel

VPN Embratel – eth2

VPN Itaboraí – tun0

*VPN sem tráfego desde 17/04/2010. Este gráfico mostra tráfego mínimo, praticamente nulo.

Page 6: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

VPN Yamana – tun1

VPN Juruti

VPN Rio Capim – tun4

VPN Zâmbia – tun6

VPN Parapigmentos*Sem atividade

Page 7: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

UeM ADM – CPU Utilization

UeM ADM – Load

UeM GW – CPU Utilization

UeM GW – Load

*Os gráficos foram comparados com os da semana anterior. Em caso de alteração significativa, é feita a análise de possível problema e relatado como observação abaixo do mesmo.

Os Gráficos não comentados foram considerados normais. Caso queira análise de algum específico, basta fazer o pedido.

Page 8: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Ipaudit Diário

- Sem informações relevantes -

Ipaudit Semanal (Top 10)

IP Host Name Incoming(bytes)

Outgoing(bytes)

Total(bytes)

200.243.057.005 uemnotes.uem.com.br 14,378,812,751 7,592,005,657 21,970,818,408

192.168.000.001 - 3,243,287,381 15,525,547,357 18,768,834,738

192.168.000.103 uemnotes.uem.com.br 6,950,523,937 743,562,749 7,694,086,686

200.243.057.011 - 1,058,966,795 5,537,465,724 6,596,432,519

192.168.014.170 - 8,267,807 6,398,529,466 6,406,797,273

192.168.014.109 - 8,702,211 5,507,710,247 5,516,412,458

192.168.014.172 - 206,744,868 2,249,698,798 2,456,443,666

200.243.057.008 - 444,381,611 159,941,736 604,323,347

192.168.000.107 uemantspam.uem.com.br 456,587,202 123,287,361 579,874,563

200.243.057.002 correio.uem.com.br 470,341,004 99,200,239 569,541,243

Squid Reports Semanal – 10/04/2011 a 17/04/2011

Squid Reports – TopSites

NUM ACCESSED SITE CONNECT BYTES TIME

1 au.download.windowsupdate.com 213.62K 7.32G 525.87M

2 osce80-en.url.trendmicro.com 192.26K 127.49M 79.14M

3 s.glbimg.com 132.08K 506.32M 31.56M

4 www.softexpert.com.br 69.00K 52.79M 5.65M

5 imagens.climatempo.com.br 38.75K 17.85M 2.94M

6 www.google.com.br 35.72K 247.21M 99.71M

7 www.google-analytics.com 35.35K 24.40M 7.88M

8 www.globo.com 32.58K 88.81M 17.62M

9 clients1.google.com.br 29.58K 23.05M 12.54M

10 pagead2.googlesyndication.com 28.13K 99.69M 10.52M

11 www.postzambia.com 27.54K 164.13M 148.42M

12 p2.trrsf.com.br 23.80K 27.93M 4.74M

13 suporte.totvs.com 23.53K 21.76M 3.73M

14 download.windowsupdate.com 21.21K 661.27M 39.05M

15 www.lancenet.com.br 21.05K 43.58M 4.71M

16 isodoc.uem.com.br 20.75K 173.50M 20.58M

17 ads.img.globo.com 20.65K 146.55M 16.93M

18 l.yimg.com 19.53K 141.36M 12.75M

19 ad.yieldmanager.com 16.83K 76.31M 16.19M

20 postzambia.com 16.59K 110.43M 78.77M

Squid Reports – TopUsers

NUM USERID CONNECT BYTES %BYTES IN-CACHE-OUT ELAPSED TIME MILISEC %TIME

1 192.168.0.68 2.13K 1.34G 4.52% 0.04% 99.96% 01:51:52 6,712,145 0.09%

2 192.168.0.19 27.00K 986.18M 3.30% 0.93% 99.07% 06:54:02 24,842,649 0.33%

3 192.168.12.171 21.56K 830.70M 2.78% 2.63% 97.37% 12:44:45 45,885,067 0.61%

4 192.168.12.236 29.64K 756.82M 2.53% 4.32% 95.68% 13:45:09 49,509,353 0.66%

5 192.168.0.12 25.19K 731.02M 2.45% 3.36% 96.64% 04:20:04 15,604,181 0.21%

6 192.168.9.201 74.77K 633.67M 2.12% 10.00% 90.00% 30:44:47 110,687,797 1.48%

7 192.168.12.234 45.43K 496.05M 1.66% 4.38% 95.62% 46:48:30 168,510,760 2.25%

8 192.168.12.191 36.29K 467.74M 1.57% 8.59% 91.41% 23:16:32 83,792,201 1.12%

9 192.168.9.112 1.67K 458.53M 1.54% 0.42% 99.58% 10:19:43 37,183,863 0.50%

10 192.168.0.44 6.40K 445.47M 1.49% 0.96% 99.04% 01:39:31 5,971,240 0.08%

11 192.168.0.176 9.49K 438.20M 1.47% 2.42% 97.58% 01:17:18 4,638,597 0.06%

12 192.168.12.108 37.58K 372.16M 1.25% 5.80% 94.20% 14:20:49 51,649,478 0.69%

13 192.168.0.173 59.85K 350.91M 1.17% 6.16% 93.84% 04:27:06 16,026,823 0.21%

14 192.168.9.106 36.89K 336.10M 1.13% 15.64% 84.36% 15:15:41 54,941,281 0.73%

Page 9: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

15 192.168.12.192 45.05K 335.20M 1.12% 11.79% 88.21% 11:12:53 40,373,677 0.54%

16 192.168.10.242 13.77K 320.56M 1.07% 13.10% 86.90% 15:36:19 56,179,003 0.75%

17 192.168.0.92 13.88K 319.40M 1.07% 11.68% 88.32% 01:27:32 5,252,447 0.07%

18 192.168.12.229 19.82K 315.79M 1.06% 10.02% 89.98% 22:04:59 79,499,234 1.06%

19 192.168.12.145 38.42K 291.91M 0.98% 7.24% 92.76% 17:24:36 62,676,505 0.84%

20 192.168.14.245 4.94K 281.91M 0.94% 3.76% 96.24% 06:42:05 24,125,142 0.32%

Squid Reports – Tentativas de acesso a Sites Indevidos

LOCAL ACESSADO IPwww.clubedaputaria.ws 192.168.12.247www.clubedaputaria.xpg.com.br 192.168.12.247www.jfsexy.com.br 192.168.0.8www.sexvenusbrasil.com 192.168.9.245www.sexychatinvite.com 192.168.12.192

Obs1: Não foi acrescentada nenhuma expressão ao arquivo /etc/squid/site_proibido.txt a fim de impedir o acesso de sites relacionados.

Page 10: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Trend Micro - InterScan Messaging Security Suite

DADOS DO SISTEMA

NOME VERSÃO CORRENTE DISPONÍVEL VERSÃO ANTERIORScan engine 9.200.1012 9.200.1012 9.200.1012Virus pattern 7.983.00 7.983.00 7.965.00Spyware/grayware pattern 0.871.00 0.871.00 0.871.00IntelliTrap pattern 0.153.00 0.153.00 0.153.00IntelliTrap exceptions 0.647.00 0.647.00 0.645.00Anti-spam engine 6.5.1024 6.5.1024 6.5.1024Spam pattern 18080.007 18080.007 18066.007IMSS Version 7.0-Build_Linux_3216 N/A

ESTATÍSTICAS

PERÍODO: ÚLTIMOS 7 DIAS

RESUMO

Scanning Conditions Total %Malicious code 48 0.09%Spyware/grayware 0 0%Spam 11506 22.34%Phish 0 0%Attachment 0 0%Size 0 0%Content 513 1%Others 0 0%Scanning exceptions 4 0.01%

GRÁFICOS – PERÍODO 10/04/2011 A 16/04/2011Spam by Action

Spam ActionsDetections Message % Size (MB)

Total spam message count 41529 100.00 180.690

Quarantined 12567 30.26 180.690

Deleted 0 0.00 0.000

Tagged 12567 30.26 180.690

Other 0 0.00 0.000

Rejected by NRS 28962 69.74 N/A

Rejected by IP Profiler 0 0.00 N/A

Page 11: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Top 10 Spam RecipientsRecipient Total Message Count Total Spam Msgs Spam Msgs % Spam Size (MB) Spam Size %

[email protected] 577 322 55.81 5.625 [email protected] 562 252 44.84 4.406 [email protected] 427 245 57.38 3.301 [email protected] 326 194 59.51 2.968 [email protected] 266 179 67.29 2.120 [email protected] 216 166 76.85 2.170 [email protected] 409 157 38.39 3.062 [email protected] 413 152 36.80 1.872 [email protected] 638 142 22.26 1.598 4.21

[email protected] 340 141 41.47 1.025 0.93

Virus and Malicious Code Summary

Detections Message %

Total detections 74 100.00

Messages deleted 2 2.70

Messages quarantined 72 97.30

Attachments cleaned 0 0.00

Messages with attachments deleted 4 5.41

Messages blocked by IP Profiler 0 0.00

Top 10 Virus and Malicious Code Detections1PAK_Generic.001 672Possible_Virus 33TROJ_BREDOLAB.DP 14PAK_Generic.005 15WORM_Mydoom.DAM 16WORM_MYDOOM.GEN 17N/A 08N/A 09N/A 0

10N/A 0

Top 10 Virus RecipientsRecipient Total Message Count Total Virus Msgs Virus Msgs % Virus Size (MB) Virus Size %

[email protected] 409 4 0.98 0.101 [email protected] 19 3 15.79 0.029 [email protected] 577 3 0.52 0.029 [email protected] 20 3 15.00 0.029 [email protected] 30 3 10.00 0.030 [email protected] 40 2 5.00 0.019 [email protected] 25 2 8.00 0.020 [email protected] 22 2 9.09 0.019 [email protected] 24 2 8.33 0.020 42.86

[email protected] 41 2 4.88 0.020 0.28

Page 12: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

CACTI – Gráficos

Período de 11/04/2011 a 18/04/2011

UEMFS

Page 13: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço
Page 14: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

UEMICA

Page 15: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

UEMNOTES

Page 16: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

UEMPRD

Page 17: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço
Page 18: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

UEMRMSA

Page 19: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço
Page 20: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Nagios

Disponibilidade – últimos 7 dias

Host Service % Time OK% Time Warning

% Time Unknown

% Time Critical

% Time Undetermined

internet_embratel Rede_Ping92.539% (92.539%)

0.000% (0.000%)

0.000% (0.000%)

7.461% (7.461%)

0.000%

uem1_Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

link-juruti Rede_Ping91.586% (91.586%)

0.049% (0.049%)

0.000% (0.000%)

8.365% (8.365%)

0.000%

uem1_Rede_Ping99.421% (99.421%)

0.000% (0.000%)

0.000% (0.000%)

0.579% (0.579%)

0.000%

link-riocapim Rede_Ping86.890% (86.890%)

0.545% (0.545%)

0.000% (0.000%)

12.565% (12.565%)

0.000%

uem1_Rede_Ping87.276% (87.276%)

0.716% (0.716%)

0.000% (0.000%)

12.008% (12.008%)

0.000%

link-yamana Rede_Ping92.615% (92.615%)

0.000% (0.000%)

0.000% (0.000%)

7.385% (7.385%)

0.000%

uem1_Rede_Ping99.941% (99.941%)

0.000% (0.000%)

0.000% (0.000%)

0.059% (0.059%)

0.000%

link-zambia Rede_Ping92.567% (92.567%)

0.000% (0.000%)

0.000% (0.000%)

7.433% (7.433%)

0.000%

uem1_Rede_Ping99.854% (99.854%)

0.000% (0.000%)

0.000% (0.000%)

0.146% (0.146%)

0.000%

nagios_remoto Rede_Http92.671% (92.671%)

0.000% (0.000%)

0.000% (0.000%)

7.329% (7.329%)

0.000%

uem1_Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

router_cisco Rede_Ping92.556% (92.556%)

0.000% (0.000%)

0.000% (0.000%)

7.444% (7.444%)

0.000%

Rede_Telnet92.556% (92.556%)

0.000% (0.000%)

0.000% (0.000%)

7.444% (7.444%)

0.000%

uem1_Rede_Ping99.904% (99.904%)

0.000% (0.000%)

0.000% (0.000%)

0.096% (0.096%)

0.000%

storage-119 Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

storage-120 Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-B Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-C Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-D Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-E Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-F Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem-adm Local_Carga100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_Root100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Processos100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Users100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Http:82100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SSH100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem-gw Local_Carga99.950% (99.950%)

0.050% (0.050%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_Root100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_backup100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Page 21: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Local_Disk_bkpremoto

99.952% (99.952%)

0.000% (0.000%)

0.000% (0.000%)

0.048% (0.048%)

0.000%

Local_Disk_ftp_pessoal

99.952% (99.952%)

0.000% (0.000%)

0.000% (0.000%)

0.048% (0.048%)

0.000%

Local_Disk_ftp_public

99.952% (99.952%)

0.000% (0.000%)

0.000% (0.000%)

0.048% (0.048%)

0.000%

Local_Disk_home_ponto

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_home_restrito

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Processos99.950% (99.950%)

0.000% (0.000%)

0.000% (0.000%)

0.050% (0.050%)

0.000%

Local_Users100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Dns100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ftp100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Http:81100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SSH100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Squid:3128100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Local_Disk_ftp_public

99.969% (99.969%)

0.000% (0.000%)

0.000% (0.000%)

0.031% (0.031%)

0.000%

uem1_Local_Disk_home_ponto

99.969% (99.969%)

0.000% (0.000%)

0.000% (0.000%)

0.031% (0.031%)

0.000%

uemantspam-imss Rede_Ping64.075% (64.075%)

0.000% (0.000%)

0.000% (0.000%)

35.925% (35.925%)

0.000%

Rede_TrendImss64.075% (64.075%)

0.000% (0.000%)

0.000% (0.000%)

35.925% (35.925%)

0.000%

Rede_TrendPolices64.075% (64.075%)

0.000% (0.000%)

0.000% (0.000%)

35.925% (35.925%)

0.000%

uemap-aplicacao Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uembdcRede_Active Directory

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Active Directory

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uembes-blackberry Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_LotusDomino98.580% (98.580%)

0.000% (0.000%)

0.000% (0.000%)

1.420% (1.420%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemdev Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SAP100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemfs-fileserver Rede_Http96.676% (96.676%)

0.000% (0.000%)

0.000% (0.000%)

3.324% (3.324%)

0.000%

Rede_NetBios99.950% (99.950%)

0.000% (0.000%)

0.000% (0.000%)

0.050% (0.050%)

0.000%

Rede_Ping99.952% (99.952%)

0.000% (0.000%)

0.000% (0.000%)

0.048% (0.048%)

0.000%

uem1_Rede_NetBios99.950% (99.950%)

0.000% (0.000%)

0.000% (0.000%)

0.050% (0.050%)

0.000%

uemica-metaframe Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Metaframe100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_TS100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Page 22: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

uem1_Rede_Metaframe

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_TS100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemmine-database Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Sql100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Sql100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemnotes-correio Rede_Https99.308% (99.308%)

0.000% (0.000%)

0.000% (0.000%)

0.692% (0.692%)

0.000%

Rede_Ldap99.308% (99.308%)

0.000% (0.000%)

0.000% (0.000%)

0.692% (0.692%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Smtp99.308% (99.308%)

0.000% (0.000%)

0.000% (0.000%)

0.692% (0.692%)

0.000%

uem1_Rede_Https99.308% (99.308%)

0.000% (0.000%)

0.000% (0.000%)

0.692% (0.692%)

0.000%

uem1_Rede_Smtp99.308% (99.308%)

0.000% (0.000%)

0.000% (0.000%)

0.692% (0.692%)

0.000%

uemprd Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SAP100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_SAP100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemrmsa-database Rede_Oracle100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Oracle100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemvm-vmware Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

vm-isodoc Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Postgresql100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Postgresql

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Average97.822% (97.822%)

0.015% (0.015%)

0.000% (0.000%)

2.163% (2.163%)

0.000%

NTOP

Page 23: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço
Page 24: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Trend Micro - Office Scan

Update Status for Networked Computers

* itens marcados com a cor amarela possuem a mesma versão da semana anterior

Top 10 Security Risk Statistics for Networked Computers

Virus/Malware Statistics:

Virus/Malware

Name Infections

HTML_IFRAME.AUO 13927

Mal_Otorun1 4040

PE_MABEZAT.B-O 3835

TSC_GENCLEAN 1827

PAK_Generic.001 1669

Mal_Sality 1607

WORM_OTOIT.SMT 1257

TROJ_Generic.DIT 1098

Mal_Otorun2 977

TROJ_DLOADE.FF 975

Infected Computers

Name Detections Log

UEMPABX 1183 View

UEMFS 744 View

UEMOP706 730 View

UEMMBB312 452 View

UEMMBB43 448 View

UEMMBB265 419 View

UEMOP965 362 View

UEMOP956 350 View

MAINTENA-C3F3A2 303 View

UEMOP509 287 View

Page 25: Relatório Semanal U&M - InvestLinux – 18/04/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 18/04/2011 Uptime / Last OK Espaço

Infection Source

Name Detections

192.168.9.242\ADMINISTRADOR 70

192.168.4.12\KEILLA REGINA 35

192.168.9.38\ADMINISTRADOR 34

\\192.168.0.133\GUEST 22

\\192.168.0.131\GUEST 21

HP-DISPATCH2\ADMINISTRATOR 20

RAR-29A45523705\ROTINARC 19

\\[fe80::c5b5:9711:6e96:4124]\Guest 16

\\UEMZMSPL\Guest 16

\\UEMZMSPL\ANONYMOUS LOGON 16

Spyware/Grayware Statistics:

Spyware/Grayware

Name Infections

GRAY_Gen 177

SPYW_ARDAKEY 170

CRCK_KEYGEN 166

HKTL_ULTRASURF 84

GRAY_GEN.0Z1013S 71

ADW_SAVENOW.BO 29

HKTL_USURF 25

CRCK_JBEAN 23

GRAY_Sml 22

ADW_WEBDIR.AC 12

Infected Computers

Name Detections Log

UEMFS 217 View

UEMPABX 171 View

UEMOP964 77 View

UEMICA 71 View

UEMMBB163 13 View

UEMMBB01 12 View

UEMOP960 7 View

UEMOP416 5 View

UEMOP965 4 View

TI05 3 View