就挂了个qBittorrent,收到邮件要不要管?这个应该是对方那边服务器通过HZ发过来的吧?
- We have received information regarding spam and/or abuse from botnet.tracker@gmail.com.
This is an information email only and does not require any further action on your part.
It is your choice whether or not to investigate the complaint.
We do not expect any response.
Information:
Hello,
This is a notification of unauthorized uses of systems or networks.
On December 11, 2022, a total of 68 IP addresses from your networks
probed my servers for TCP open ports.Due to their dubious behavior, they
are suspected to be compromised botnet computers.
The log of TCP port scans is included below for your reference
(time zone is UTC).To prevent this mail from getting too big in size,
at most 5 attempts from each attacker IP are included.Those connection
attempts have all passed TCP's 3-way handshake, so you can trust the source
IP addresses to be correct.
If you regularly collect IP traffic information of your network, you will see
the IPs listed connected to various TCP ports of my server at the time logged,
and I suspect that they also connected to TCP ports of many other IPs.
If a Linux system was at the attacker's IP, you might want to use the
command "ss -ntp" to list its active network connections.If there
is still some suspicious connection, find out what PID/program/user ID they
belong to.You might find something to help you solve this problem.
Please notify the victims (owners of those botnet computers) so that they
can take appropriate action to clean their computers, before even
more severe incidents, like data leakage, DDoS, and the rumored NSA spying
through hijacked botnets, arise.This also helps prevent botnets from
taking up your network bandwidth.
Chih-Cherng Chin
Daily Botnet Statistics
---- log of TCP port scans (time zone is UTC; sent to abuse@hetzner.com) ----
-------------------------------------------------------------------------------
(time in UTC)=2022-12-11T23:08:58 (attacker's IP)=116.203.1.1 (IP being scanned)=61^61^170^12 (TCP port being scanned)=7547
(time in UTC)=2022-12-11T23:08:58 (attacker's IP)=116.203.1.1 (IP being scanned)=61^61^170^12 (TCP port being scanned)=7547
热议
推荐楼 雨墨 昨天22:59
跟你情况一样
/**
* Linux常用命令:rsync -rogpav --delete /home /tmp 同步两边的目录
* 垂死病中惊坐起,笑问客从何处来
* Link https://greasyfork.org/zh-CN/scripts/396933-hostloc-zsbd
*/
3楼 Rebel 昨天23:00
跟你情况一样
应该没啥事吧,我收到两封,有一封里面的IP还是VIR的,谁用VIR刷PT,连别人服务器下载VIR还反向告状,操
4楼 雨墨 昨天23:08
应该没啥事吧,我收到两封,有一封里面的IP还是VIR的,谁用VIR刷PT,连别人服务器下载VIR还反向告状,操: ...
我都不知道啥情况管他干鸡毛再发直接删鸡
5楼 toot 昨天23:21
挺好的。老老实实建站的可以上了。邻居搞不了事情
6楼 finial2006 13小时前
不回会封号
7楼 liugogal 13小时前
我不清楚你邮件是不是复制全了,要回abuse的邮件里面会有个链接的,打开后会要求你写明情况附上abuse的id
8楼 Rebel 13小时前
我不清楚你邮件是不是复制全了,要回abuse的邮件里面会有个链接的,打开后会要求你写明情况附上abuse的id ...
没有链接,只说要保留abuse id,我直接回的邮件
9楼 bcdefg 9小时前
我都不知道啥情况管他干鸡毛再发直接删鸡
拜托你读读邮件中的英文内容,你的机子是被爆破当肉鸡了,和楼主不一样
10楼 mnihyc 9小时前
This is an information email only and does not require any further action on your part.
12楼 ReActRailGun 1小时前
This is an information email only and does not require any further action on your part.
It is your choice whether or not to investigate the complaint.
We do not expect any response.
这只是一封信息电子邮件,不需要您采取任何进一步行动。
是否调查投诉是您的选择。
我们预计不会有任何回应。
申明:本文内容由网友收集分享,仅供学习参考使用。如文中内容侵犯到您的利益,请在文章下方留言,本站会第一时间进行处理。
评论前必须登录!
立即登录 注册