F
F
fStrange2022-03-20 20:50:51
*nix-like systems
fStrange, 2022-03-20 20:50:51

Abuse from Hetzner and ban, where to look?

The hoster received an abuse from Hetzner and banned the server.

################################################## ########################
> # Netscan detected from host 217.12.xx.xx #
> ############# ################################################## ###########
>
> time protocol src_ip src_port dest_ip dest_port
> ------------------------------ ----------------------------------------------------
> Fri Mar 18 20 :02:18 2022 UDP 217.12.xx.xx 10651 => 5.75.128.0 123
> Fri Mar 18 20:02:18 2022 UDP 217.12.xx.xx 13423 => 5.75.128.1 123
> Fri Mar 18 20:02:18 2022 UDP 217.12.xx.xx 28049 => 5.75.128.2 123
> Fri Mar 18
20:02:18 xx.xx 25829 => 5.75.128.4 123


The server is currently unblocked. Where to dig?
I don’t see any suspicious network activity at the moment, I checked for rootkits, it’s clean. There is nothing suspicious in the crontasks.

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question