I keep getting inbound blocked messages in my logs from the same ip address which is based in Ukraine.
I have changed my wan ip address like 50 times with different subnets and whenever i turn on my wan connection logs start screaming
Main targeted port is tcp 46112 which i think hosts radio communication devices.
Could it be an installed software which is leaking my ip address to the attacker?
Virus Total Result Says It's Malware.
I have changed my wan ip address like 50 times with different subnets and whenever i turn on my wan connection logs start screaming
Code:
Aug 13 02:25:04 GT-AX11000-CF50 kernel: [BLOCKED - INBOUND] IN=ppp0 OUT= MAC= SRC=31.43.191.143 DST=(My Ip Goes Here) LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=40627 PROTO=TCP SPT=46112 DPT=13915 SEQ=4231858985 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Could it be an installed software which is leaking my ip address to the attacker?
Virus Total Result Says It's Malware.