Skynet and AiProtection
So just to appease my own curiosity...
I see 80.211.185.70 in my aiprotect logs
Code:
External Attacks 80.211.185.70 192.168.1.102 WEB GoAhead login.cgi Information Disclosure Vulnerability
2018-07-27 00:45:52
I check and see that its an italian ip address which is not part of my country blocks
https://myip.ms/info/whois/80.211.185.70
I check and see that it was added to my skynet blacklist
Code:
ipset -L Skynet-Blacklist | grep AiProtect
80.211.185.70 comment "BanAiProtect"
I see other traffic now being blocked to that ip address that did not trigger aiprotect
Code:
Line 415468: <4>1 2018-07-27T04:41:17-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=48164 DPT=81 SEQ=576578511 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 415759: <4>1 2018-07-27T07:16:49-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=50380 DPT=81 SEQ=410143747 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 417409: <4>1 2018-07-27T23:44:30-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=41787 DPT=81 SEQ=2319680743 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 417467: <4>1 2018-07-28T00:04:04-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=45008 DPT=81 SEQ=1887447114 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 417594: <4>1 2018-07-28T01:32:08-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=34666 DPT=81 SEQ=2458031098 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 417632: <4>1 2018-07-28T01:55:38-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=59538 DPT=81 SEQ=3294947754 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 417759: <4>1 2018-07-28T03:24:50-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=58376 DPT=81 SEQ=1282468763 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 417855: <4>1 2018-07-28T04:31:41-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=43674 DPT=81 SEQ=3633484248 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 418247: <4>1 2018-07-28T09:09:32-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=48933 DPT=81 SEQ=2274426019 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 418357: <4>1 2018-07-28T10:24:58-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=41095 DPT=81 SEQ=1083644364 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 418668: <4>1 2018-07-28T13:51:25-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=35720 DPT=81 SEQ=3868071557 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 418813: <4>1 2018-07-28T15:16:14-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=37721 DPT=81 SEQ=2449528176 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Line 418849: <4>1 2018-07-28T15:43:39-07:00 192.168.1.1 kernel - - - kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=2c:4d:54:21:17:f0:00:01:5c:6d:58:46:08:00 SRC=80.211.185.70 DST=23.242.44.106 LEN=40 TOS=0x00 PREC=0x00 TTL=235 ID=54321 PROTO=TCP SPT=55845 DPT=81 SEQ=3822381768 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0
Search "89.248.174.45" (324 hits in 1 file)
this is freaking awesome!
I'm a little surprised by the uniqueness of the ips though. I only see this for a small sampling of the ip addresses that aiprotect caught.