What's new

Skynet Outbound blocks

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

BeachGuy

Senior Member
I have 47 outbound blocks from my router (Skynet reports my router's WAN IP) to IP 91.212.166.118. When I click on the link in Skynet it brings me to AlienVault and says Great Britain and Northern Ireland. When I click on "whois" it says Russia. I'm not sure how to interpret the data on those websites but am concerned the router is sending anything out that's blocked. Where/why would the router be sending this from? I use unbound, diversion and skynet. What should I do?

P.S.
I do have the TOR browser and have used that a couple of times today. Could that be it?



firewall stats search ip 91.212.166.118
#############################################################################################################
# #
# ███████╗██╗ ██╗██╗ ██╗███╗ ██╗███████╗████████╗ ██╗ ██╗███████╗ #
# ██╔════╝██║ ██╔╝╚██╗ ██╔╝████╗ ██║██╔════╝╚══██╔══╝ ██║ ██║╚════██║ #
# ███████╗█████╔╝ ╚████╔╝ ██╔██╗ ██║█████╗ ██║ ██║ ██║ ██╔╝ #
# ╚════██║██╔═██╗ ╚██╔╝ ██║╚██╗██║██╔══╝ ██║ ╚██╗ ██╔╝ ██╔╝ #
# ███████║██║ ██╗ ██║ ██║ ╚████║███████╗ ██║ ╚████╔╝ ██║ #
# ╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝ ╚═══╝╚══════╝ ╚═╝ ╚═══╝ ╚═╝ #
# #
# Router Firewall And Security Enhancements #
# By Adamm - https://github.com/Adamm00/IPSet_ASUS #
# 02/07/2024 - v7.6.1 #
#############################################################################################################


=============================================================================================================


Logging Data Detected in /tmp/mnt/ROUTER/skynet/skynet.log - 4.5M
Monitoring From Jul 18 21:00:09 To Jul 20 04:48:58
16496 Block Events Detected
2970 Unique IPs
0 Manual Bans Issued

91.212.166.118 is NOT in set Skynet-Whitelist.
91.212.166.118 is NOT in set Skynet-Blacklist.
Warning: 91.212.166.118 is in set Skynet-BlockedRanges.

BlockedRanges Reason;

91.212.166.0/24 "BanMalware: et_block.netset"

IP Location - Russia (Proton66 OOO / AS198953)

91.212.166.118 First Tracked On Jul 19 13:30:00
91.212.166.118 Last Tracked On Jul 19 13:30:01
47 Blocks Total

Event Log Entries From 91.212.166.118;

First Block Tracked From 91.212.166.118;
Jul 19 13:30:00 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=74 TOS=0x00 PREC=0x00 TTL=64 ID=24500 PROTO=UDP SPT=34994 DPT=53 LEN=54

10 Most Recent Blocks From 91.212.166.118;
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24858 PROTO=UDP SPT=41049 DPT=53 LEN=58
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24864 PROTO=UDP SPT=60967 DPT=53 LEN=58
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24876 PROTO=UDP SPT=37636 DPT=53 LEN=58
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24883 PROTO=UDP SPT=20023 DPT=53 LEN=58
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24892 PROTO=UDP SPT=36667 DPT=53 LEN=58
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24899 PROTO=UDP SPT=12063 DPT=53 LEN=58
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24902 PROTO=UDP SPT=30030 DPT=53 LEN=58
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24913 PROTO=UDP SPT=52516 DPT=53 LEN=58
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24919 PROTO=UDP SPT=45708 DPT=53 LEN=58
Jul 19 13:30:01 kernel: [BLOCKED - OUTBOUND] IN= OUT=eth0 SRC=WAN IP DST=91.212.166.118 LEN=78 TOS=0x00 PREC=0x00 TTL=64 ID=24931 PROTO=UDP SPT=22682 DPT=53 LEN=58


Top 10 Targeted Ports From 91.212.166.118 (Inbound);


-------- | -------- | --------------
| Hits | | | Port | | | SpeedGuide |
-------- | -------- | --------------

--*

Top 10 Sourced Ports From 91.212.166.118 (Inbound);


-------- | -------- | --------------
| Hits | | | Port | | | SpeedGuide |
-------- | -------- | --------------

*--


=============================================================================================================


[#] 33459 IPs (+0) -- 2848 Ranges Banned (+0) || 16450 Inbound -- 47 Outbound Connections Blocked! [stats] [17s]
 
Last edited:
I just ran TOR browser again and the number of outbound blocks didn't change leading me to believe it's not the TOR browser.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top