Hallo Leute,
seit einiger Zeit habe ich merkwürdige Netzwerkmeldungen im Log:
Dabei ist 192.168.2.9 mein Medienserver, von dem dieser Log-Auszug stammt.Code:Feb 05 09:30:04 esprimo kernel: SFW2-INext-ACC-TCP IN=enp0s25 OUT= MAC=00:01:80:68:f2:aa:ac:9e:17:b4:3b:aa:08:00 SRC=192.168.2.20 DST=192.168.2.9 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=51082 DF PROTO=TCP SPT=38113 DPT=443 WINDOW=29200 RES=0x00 SYN URGP=0 OPT (020405B40402080A0017325C0000000001030307) Feb 05 09:30:34 esprimo kernel: SFW2-INext-ACC-TCP IN=enp0s25 OUT= MAC=00:01:80:68:f2:aa:ac:9e:17:b4:3b:aa:08:00 SRC=192.168.2.20 DST=192.168.2.9 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=25759 DF PROTO=TCP SPT=38115 DPT=443 WINDOW=29200 RES=0x00 SYN URGP=0 OPT (020405B40402080A00174FAD0000000001030307) Feb 05 09:30:50 esprimo kernel: SFW2-INext-DROP-DEFLT IN=enp0s25 OUT= MAC=00:01:80:68:f2:aa:24:65:11:f4:21:ef:08:00 SRC=192.168.2.1 DST=192.168.2.9 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=6385 DF PROTO=TCP SPT=37265 DPT=14013 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A05F5BEF00000000001030302) Feb 05 09:30:50 esprimo kernel: SFW2-INext-ACC-TCP IN=enp0s25 OUT= MAC=00:01:80:68:f2:aa:00:11:e0:03:c3:85:08:00 SRC=192.168.2.142 DST=192.168.2.9 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=58739 DF PROTO=TCP SPT=55707 DPT=9000 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A01DB9F7C0000000001030301) Feb 05 09:30:53 esprimo kernel: SFW2-INext-DROP-DEFLT IN=enp0s25 OUT= MAC=00:01:80:68:f2:aa:24:65:11:f4:21:ef:08:00 SRC=192.168.2.1 DST=192.168.2.9 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=6386 DF PROTO=TCP SPT=37265 DPT=14013 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A05F5C01C0000000001030302) Feb 05 09:30:59 esprimo kernel: SFW2-INext-DROP-DEFLT IN=enp0s25 OUT= MAC=00:01:80:68:f2:aa:24:65:11:f4:21:ef:08:00 SRC=192.168.2.1 DST=192.168.2.9 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=6387 DF PROTO=TCP SPT=37265 DPT=14013 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A05F5C2740000000001030302) Feb 05 09:31:04 esprimo kernel: SFW2-INext-ACC-TCP IN=enp0s25 OUT= MAC=00:01:80:68:f2:aa:ac:9e:17:b4:3b:aa:08:00 SRC=192.168.2.20 DST=192.168.2.9 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=15789 DF PROTO=TCP SPT=38116 DPT=443 WINDOW=29200 RES=0x00 SYN URGP=0 OPT (020405B40402080A00176CF80000000001030307) Feb 05 09:31:34 esprimo kernel: SFW2-INext-ACC-TCP IN=enp0s25 OUT= MAC=00:01:80:68:f2:aa:ac:9e:17:b4:3b:aa:08:00 SRC=192.168.2.20 DST=192.168.2.9 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=22141 DF PROTO=TCP SPT=38119 DPT=443 WINDOW=29200 RES=0x00 SYN URGP=0 OPT (020405B40402080A00178A430000000001030307) Feb 05 09:31:36 esprimo kernel: SFW2-INext-ACC-TCP IN=enp0s25 OUT= MAC=00:01:80:68:f2:aa:00:11:e0:03:e0:62:08:00 SRC=192.168.2.11 DST=192.168.2.9 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=60176 DF PROTO=TCP SPT=57616 DPT=9000 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B4)
Kann es sein, dass ich mir einen Virus eingefangen habe?
Lesezeichen