DonnyJohnny
Very Senior Member
The ISP is likely to be under some kind of massive port scanning... the log mainly came from 2 group of IPs as per below.The output is correct, your logs were purged at 9pm. There’s a few hour gap without reports, but it looks like you managed to amass 12,000 hits in 8hours so the syslog probably purged itself before Skynet could. Although that amount of hits (compared to my single user results) seems pretty high. By the looks of it your using extra lists, so may be worth investigating what’s list is causing the significiant amount of extra hits and if it’s nessesasy. But at the end of the day that’s user preference, so if it works for you then by all means go for it.
Nothing to worry about, this just dumps the IPSet data from ram to the physical copy on your USB (skynet.ipset) which Skynet does every hour in a cronjob or commands that modify data.
Code:
Top 50 Blocks (Inbound);
2599x https://otx.alienvault.com/indicator/ip/194.28.112.50
446x https://otx.alienvault.com/indicator/ip/5.188.62.243
429x https://otx.alienvault.com/indicator/ip/5.188.62.171
423x https://otx.alienvault.com/indicator/ip/5.188.62.20
419x https://otx.alienvault.com/indicator/ip/5.188.62.17
412x https://otx.alienvault.com/indicator/ip/5.188.62.180
406x https://otx.alienvault.com/indicator/ip/5.188.62.174
405x https://otx.alienvault.com/indicator/ip/95.215.0.167
405x https://otx.alienvault.com/indicator/ip/5.188.62.172
404x https://otx.alienvault.com/indicator/ip/5.188.62.18
404x https://otx.alienvault.com/indicator/ip/5.188.62.175
403x https://otx.alienvault.com/indicator/ip/5.188.62.173
400x https://otx.alienvault.com/indicator/ip/5.188.62.7
394x https://otx.alienvault.com/indicator/ip/5.188.62.245
392x https://otx.alienvault.com/indicator/ip/5.188.62.244
391x https://otx.alienvault.com/indicator/ip/5.188.62.167
387x https://otx.alienvault.com/indicator/ip/5.188.62.112
378x https://otx.alienvault.com/indicator/ip/5.188.62.15
375x https://otx.alienvault.com/indicator/ip/5.188.62.249
370x https://otx.alienvault.com/indicator/ip/5.188.62.71
367x https://otx.alienvault.com/indicator/ip/5.188.62.242
365x https://otx.alienvault.com/indicator/ip/5.188.62.240
353x https://otx.alienvault.com/indicator/ip/5.188.62.91
14x https://otx.alienvault.com/indicator/ip/191.101.167.26
12x https://otx.alienvault.com/indicator/ip/77.72.82.103
10x https://otx.alienvault.com/indicator/ip/5.188.11.35
10x https://otx.alienvault.com/indicator/ip/5.188.11.25
9x https://otx.alienvault.com/indicator/ip/181.214.87.95
9x https://otx.alienvault.com/indicator/ip/181.214.87.91
8x https://otx.alienvault.com/indicator/ip/181.214.87.96
8x https://otx.alienvault.com/indicator/ip/181.214.87.93
8x https://otx.alienvault.com/indicator/ip/181.214.87.88
8x https://otx.alienvault.com/indicator/ip/146.120.123.63
7x https://otx.alienvault.com/indicator/ip/5.188.11.24
7x https://otx.alienvault.com/indicator/ip/5.178.167.182
6x https://otx.alienvault.com/indicator/ip/92.38.32.178
6x https://otx.alienvault.com/indicator/ip/79.134.220.46
6x https://otx.alienvault.com/indicator/ip/77.93.31.99
6x https://otx.alienvault.com/indicator/ip/192.251.231.111
6x https://otx.alienvault.com/indicator/ip/185.56.81.51
6x https://otx.alienvault.com/indicator/ip/185.143.223.201
6x https://otx.alienvault.com/indicator/ip/181.214.87.90
6x https://otx.alienvault.com/indicator/ip/181.214.87.89
5x https://otx.alienvault.com/indicator/ip/95.46.74.118
5x https://otx.alienvault.com/indicator/ip/93.171.31.131
5x https://otx.alienvault.com/indicator/ip/79.133.242.221
5x https://otx.alienvault.com/indicator/ip/181.214.87.94
5x https://otx.alienvault.com/indicator/ip/103.207.39.195
4x https://otx.alienvault.com/indicator/ip/95.213.130.90
4x https://otx.alienvault.com/indicator/ip/95.104.75.183
Everytime when I see crazy volume of Attack from http://www.digitalattackmap.com/, my isp range is always entertained by those attacks.
Last edited: