I'm logging failures in messages.log:
Apr 19 03:40:01 * kernel: [8037514.324554] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=64659 DF PROTO=TCP SPT=40114 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 03:40:02 * kernel: [8037515.324066] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=64660 DF PROTO=TCP SPT=40114 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 03:40:06 * kernel: [8037519.351180] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=35930 DF PROTO=TCP SPT=40152 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 03:40:07 * kernel: [8037520.351071] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=35931 DF PROTO=TCP SPT=40152 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 15:40:02 * kernel: [8080715.174015] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=16265 DF PROTO=TCP SPT=47624 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 15:40:03 * kernel: [8080716.176061] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=16266 DF PROTO=TCP SPT=47624 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 15:40:07 * kernel: [8080720.395095] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=64397 DF PROTO=TCP SPT=47660 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 15:40:08 * kernel: [8080721.395103] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=64398 DF PROTO=TCP SPT=47660 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
UID 502 = cpanel:x:32001:502::/var/cpanel/userhomes/cpanel:/usr/local/cpanel/bin/noshell
Looks like a cron job calling that IP, but it's not listed in .HttpRequest:
NetRange: 67.207.64.0 - 67.207.95.255
CIDR: 67.207.64.0/19
NetName: DIGITALOCEAN-67-207-64-0
I have that netrange blocked because of repeated intrusion attempts from many, many different IPs on that range of Digital Ocean.
Anyone have any idea what this might be? Legitimate or not?
Apr 19 03:40:01 * kernel: [8037514.324554] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=64659 DF PROTO=TCP SPT=40114 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 03:40:02 * kernel: [8037515.324066] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=64660 DF PROTO=TCP SPT=40114 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 03:40:06 * kernel: [8037519.351180] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=35930 DF PROTO=TCP SPT=40152 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 03:40:07 * kernel: [8037520.351071] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=35931 DF PROTO=TCP SPT=40152 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 15:40:02 * kernel: [8080715.174015] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=16265 DF PROTO=TCP SPT=47624 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 15:40:03 * kernel: [8080716.176061] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=16266 DF PROTO=TCP SPT=47624 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 15:40:07 * kernel: [8080720.395095] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=64397 DF PROTO=TCP SPT=47660 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
Apr 19 15:40:08 * kernel: [8080721.395103] Firewall: *TCP_OUT Blocked* IN= OUT=eth5 SRC=**.**.**.** DST=67.207.68.102 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=64398 DF PROTO=TCP SPT=47660 DPT=443 WINDOW=14600 RES=0x00 SYN URGP=0 UID=502 GID=513
UID 502 = cpanel:x:32001:502::/var/cpanel/userhomes/cpanel:/usr/local/cpanel/bin/noshell
Looks like a cron job calling that IP, but it's not listed in .HttpRequest:
NetRange: 67.207.64.0 - 67.207.95.255
CIDR: 67.207.64.0/19
NetName: DIGITALOCEAN-67-207-64-0
I have that netrange blocked because of repeated intrusion attempts from many, many different IPs on that range of Digital Ocean.
Anyone have any idea what this might be? Legitimate or not?