IP´s desconhecidos na rede - Bloquear via firewall

1. IP´s desconhecidos na rede - Bloquear via firewall

HEBER FERREIRA DA MOTA
hmota

(usa CentOS)

Enviado em 17/09/2013 - 09:51h

Bom-dia pessoal.

De quinta-feira para cá venho notando um tráfego muito esquisito em minha rede. Creio que seja alguma máquina com spam que esta fazendo toda essa comunicação.

Como parar isso ? Alguma regra no firewall ?

Vou colocar o relatório do squid para vcs darem uma olhada. Obrigado.

NUM USUÁRIO CONEXÃO BYTES %BYTES IN-CACHE-OUT TEMPO GASTO MILISEG %TEMPO
40 111-248-114-118.dynamic.hinet.net 383 616.90K 0.02% 100.00% 0.00% 00:00:02 2.595 0.00%
41 111-248-59-51.dynamic.hinet.net 380 612.57K 0.02% 100.00% 0.00% 00:00:01 1.164 0.00%
42 111-241-46-73.dynamic.hinet.net 336 541.11K 0.02% 100.00% 0.00% 00:00:02 2.242 0.00%
43 111-248-113-2.dynamic.hinet.net 304 489.63K 0.02% 100.00% 0.00% 00:00:01 1.773 0.00%
44 111-248-62-49.dynamic.hinet.net 269 433.22K 0.01% 100.00% 0.00% 00:00:01 1.892 0.00%
45 111-241-47-57.dynamic.hinet.net 245 395.00K 0.01% 100.00% 0.00% 00:00:01 1.808 0.00%
46 111-241-46-124.dynamic.hinet.net 218 351.08K 0.01% 100.00% 0.00% 00:00:01 1.297 0.00%
47 61-231-93-165.dynamic.hinet.net 213 343.06K 0.01% 100.00% 0.00% 00:00:01 1.055 0.00%
48 111-248-60-106.dynamic.hinet.net 206 332.12K 0.01% 100.00% 0.00% 00:00:00 554 0.00%
49 61-228-25-170.dynamic.hinet.net 202 325.48K 0.01% 100.00% 0.00% 00:00:01 1.518 0.00%
50 111-248-56-73.dynamic.hinet.net 201 324.07K 0.01% 100.00% 0.00% 00:00:00 714 0.00%
51 61-228-31-15.dynamic.hinet.net 187 301.17K 0.01% 100.00% 0.00% 00:01:01 61.340 0.04%
52 61-231-93-2.dynamic.hinet.net 173 278.72K 0.01% 100.00% 0.00% 00:00:01 1.097 0.00%
53 61-228-20-110.dynamic.hinet.net 165 265.80K 0.01% 100.00% 0.00% 00:00:01 1.089 0.00%
54 61-228-30-158.dynamic.hinet.net 163 262.85K 0.01% 100.00% 0.00% 00:00:00 474 0.00%
55 61-231-90-134.dynamic.hinet.net 161 259.61K 0.01% 100.00% 0.00% 00:00:00 776 0.00%
56 111-248-61-50.dynamic.hinet.net 159 256.35K 0.01% 100.00% 0.00% 00:00:00 798 0.00%
57 111-248-113-127.dynamic.hinet.net 157 253.11K 0.01% 100.00% 0.00% 00:00:00 471 0.00%
58 61-231-1-20.dynamic.hinet.net 144 231.95K 0.01% 100.00% 0.00% 00:00:00 404 0.00%
59 111-248-57-151.dynamic.hinet.net 142 228.72K 0.01% 100.00% 0.00% 00:00:00 891 0.00%
60 111-241-39-41.dynamic.hinet.net 137 220.90K 0.01% 100.00% 0.00% 00:00:00 860 0.00%
61 61-228-26-36.dynamic.hinet.net 137 220.83K 0.01% 100.00% 0.00% 00:00:00 624 0.00%
62 61-231-92-85.dynamic.hinet.net 127 204.76K 0.01% 100.00% 0.00% 00:00:00 439 0.00%
63 61-228-23-98.dynamic.hinet.net 106 170.75K 0.01% 100.00% 0.00% 00:00:00 976 0.00%
64 61-228-29-8.dynamic.hinet.net 117 169.30K 0.01% 79.92% 20.08% 00:00:08 8.043 0.01%
65 111-248-57-233.dynamic.hinet.net 118 169.17K 0.01% 83.82% 16.18% 00:00:07 7.711 0.00%
66 111-241-35-89.dynamic.hinet.net 117 168.78K 0.01% 79.12% 20.88% 00:00:08 8.278 0.01%
67 61-231-5-134.dynamic.hinet.net 117 167.58K 0.01% 82.63% 17.37% 00:00:12 12.017 0.01%
68 111-248-59-106.dynamic.hinet.net 115 167.34K 0.01% 83.76% 16.24% 00:00:09 9.849 0.01%
69 111-248-117-210.dynamic.hinet.net 115 167.01K 0.01% 82.98% 17.02% 00:00:09 9.700 0.01%
70 61-231-91-232.dynamic.hinet.net 116 165.33K 0.01% 80.82% 19.18% 00:00:09 9.449 0.01%
71 111-248-114-250.dynamic.hinet.net 114 165.31K 0.01% 79.84% 20.16% 00:00:06 6.987 0.00%
72 111-248-116-92.dynamic.hinet.net 114 164.13K 0.01% 80.40% 19.60% 00:00:07 7.671 0.00%
73 61-228-28-137.dynamic.hinet.net 100 161.24K 0.01% 100.00% 0.00% 00:00:18 18.933 0.01%
74 61-228-88-8.dynamic.hinet.net 110 160.38K 0.01% 82.35% 17.65% 00:00:07 7.535 0.00%
75 111-248-115-222.dynamic.hinet.net 96 154.79K 0.00% 100.00% 0.00% 00:00:00 330 0.00%
76 111-248-114-2.dynamic.hinet.net 95 153.04K 0.00% 100.00% 0.00% 00:00:00 722 0.00%
77 61-228-88-170.dynamic.hinet.net 109 150.74K 0.00% 76.39% 23.61% 00:00:08 8.779 0.01%
78 111-248-116-149.dynamic.hinet.net 92 148.33K 0.00% 100.00% 0.00% 00:00:00 399 0.00%
79 61-231-89-82.dynamic.hinet.net 92 148.19K 0.00% 100.00% 0.00% 00:00:00 370 0.00%
80 61-228-21-9.dynamic.hinet.net 110 146.85K 0.00% 78.42% 21.58% 00:00:09 9.517 0.01%
81 61-231-81-145.dynamic.hinet.net 108 146.83K 0.00% 77.32% 22.68% 00:00:08 8.624 0.01%
82 111-248-61-18.dynamic.hinet.net 91 146.59K 0.00% 100.00% 0.00% 00:00:00 197 0.00%
83 61-231-83-129.dynamic.hinet.net 102 143.92K 0.00% 75.51% 24.49% 00:00:08 8.145 0.01%
84 111-241-40-204.dynamic.hinet.net 104 143.57K 0.00% 75.69% 24.31% 00:00:09 9.145 0.01%
85 111-248-115-22.dynamic.hinet.net 101 142.55K 0.00% 76.23% 23.77% 00:00:18 18.304 0.01%
86 61-231-3-6.dynamic.hinet.net 99 140.35K 0.00% 76.27% 23.73% 00:00:08 8.917 0.01%
87 61-231-84-229.dynamic.hinet.net 86 138.52K 0.00% 100.00% 0.00% 00:00:00 271 0.00%
88 111-241-47-172.dynamic.hinet.net 86 138.52K 0.00% 100.00% 0.00% 00:00:00 640 0.00%
89 61-231-90-118.dynamic.hinet.net 85 137.03K 0.00% 100.00% 0.00% 00:00:00 514 0.00%
90 61-231-84-253.dynamic.hinet.net 100 136.10K 0.00% 77.46% 22.54% 00:00:07 7.609 0.00%
91 111-248-62-13.dynamic.hinet.net 82 132.14K 0.00% 100.00% 0.00% 00:00:00 205 0.00%
92 61-228-89-74.dynamic.hinet.net 79 127.36K 0.00% 100.00% 0.00% 00:00:00 877 0.00%
93 111-248-112-35.dynamic.hinet.net 77 124.04K 0.00% 100.00% 0.00% 00:00:00 382 0.00%
94 111-241-36-115.dynamic.hinet.net 87 123.38K 0.00% 76.60% 23.40% 00:00:08 8.684 0.01%
95 61-231-88-174.dynamic.hinet.net 76 122.46K 0.00% 100.00% 0.00% 00:00:00 801 0.00%
96 61-228-92-201.dynamic.hinet.net 70 112.87K 0.00% 100.00% 0.00% 00:00:00 406 0.00%
97 111-241-45-9.dynamic.hinet.net 69 111.23K 0.00% 100.00% 0.00% 00:00:00 194 0.00%
98 61-231-5-198.dynamic.hinet.net 68 109.57K 0.00% 100.00% 0.00% 00:00:00 928 0.00%
99 111-248-56-136.dynamic.hinet.net 65 104.77K 0.00% 100.00% 0.00% 00:00:00 291 0.00%
100 36-230-254-126.dynamic-ip.hinet.net 60 96.74K 0.00% 100.00% 0.00% 00:00:00 548 0.00%
101 111-248-59-81.dynamic.hinet.net 60 96.67K 0.00% 100.00% 0.00% 00:00:00 168 0.00%
102 111-248-114-176.dynamic.hinet.net 53 85.40K 0.00% 100.00% 0.00% 00:00:00 242 0.00%
103 111-248-119-189.dynamic.hinet.net 53 85.39K 0.00% 100.00% 0.00% 00:00:00 135 0.00%
104 61-231-4-27.dynamic.hinet.net 50 70.41K 0.00% 80.63% 19.37% 00:00:03 3.487 0.00%
105 111-241-24-35.dynamic.hinet.net 41 66.08K 0.00% 100.00% 0.00% 00:00:00 162 0.00%
106 61-231-93-159.dynamic.hinet.net 39 62.88K 0.00% 100.00% 0.00% 00:00:00 170 0.00%
107 61-228-19-48.dynamic.hinet.net 39 62.81K 0.00% 100.00% 0.00% 00:00:00 122 0.00%
108 36-231-254-191.dynamic-ip.hinet.net 38 61.23K 0.00% 100.00% 0.00% 00:00:00 107 0.00%
109 DHCP195 50 58.07K 0.00% 98.09% 1.91% 00:00:03 3.518 0.00%
110 61-228-93-145.dynamic.hinet.net 33 53.19K 0.00% 100.00% 0.00% 00:00:00 130 0.00%
111 111-241-44-8.dynamic.hinet.net 28 45.11K 0.00% 100.00% 0.00% 00:00:00 124 0.00%
112 DHCP190 38 41.33K 0.00% 97.98% 2.02% 00:00:03 3.212 0.00%
113 111-248-58-94.dynamic.hinet.net 20 32.25K 0.00% 100.00% 0.00% 00:00:00 85 0.00%
114 Servidor MGF 14 21.77K 0.00% 16.76% 83.24% 00:00:02 2.358 0.00%
115 111-248-62-219.dynamic.hinet.net 12 16.64K 0.00% 87.72% 12.28% 00:00:00 851 0.00%
116 DHCP193 13 13.41K 0.00% 95.86% 4.14% 00:00:00 542 0.00%
117 111-248-115-69.dynamic.hinet.net 6 7.48K 0.00% 65.05% 34.95% 00:00:00 697 0.00%
118 120.112.56.121.broad.cf.nm.dynamic.163data.com.cn 3 4.84K 0.00% 100.00% 0.00% 00:00:00 241 0.00%
119 111-248-116-62.dynamic.hinet.net 2 3.21K 0.00% 100.00% 0.00% 00:00:00 5 0.00%
120 111-248-56-89.dynamic.hinet.net 2 2.30K 0.00% 70.48% 29.52% 00:00:00 291 0.00%
121 111-248-57-88.dynamic.hinet.net 1 1.62K 0.00% 100.00% 0.00% 00:00:00 14 0.00%



  


2. Re: IP´s desconhecidos na rede - Bloquear via firewall

Daniel Lara Souza
danniel-lara

(usa Fedora)

Enviado em 17/09/2013 - 09:53h

tu podes usar o iptraf e verificar qual maquina que esta infectada e formatar


3. Re: IP´s desconhecidos na rede - Bloquear via firewall

HEBER FERREIRA DA MOTA
hmota

(usa CentOS)

Enviado em 17/09/2013 - 10:07h

Ei Daniel, bom-dia.

Poderia me dar umas dicas de como implantar esse Iptraf ?


4. Re: IP´s desconhecidos na rede - Bloquear via firewall

HEBER FERREIRA DA MOTA
hmota

(usa CentOS)

Enviado em 02/10/2013 - 08:10h

Alguém teria alguma ideia .... esse tráfego ainda continua com os domínios .dynamic-ip.hinet.net e .dynamic.hinet.net todos antecedidos de um número de IP.

Fico aguardando.


5. Re: IP´s desconhecidos na rede - Bloquear via firewall

Perfil removido
removido

(usa Nenhuma)

Enviado em 02/10/2013 - 08:27h

Esse IP é externo, não é de nenhuma máquina local da sua rede. Pelo que vi aqui, o IP está localizado em Taiwan.

Talvez ele esteja tentando acesso através de bruteforce ou tentando um DDoS. Usa o Iptables pra bloquear o IP e fim de problemas. (:






Patrocínio

Site hospedado pelo provedor RedeHost.
Linux banner

Destaques

Artigos

Dicas

Tópicos

Top 10 do mês

Scripts