|
用的原作者的 https://github.com/nondanee/UnblockNeteaseMusic
结果发现一直访问奇怪的ip和网址, 这是被植入后门了?
装在另一台vps也是这个情况
- unblockneteasemusic_1 | MITM > 198.245.60.162:9101unblockneteasemusic_1 | MITM > 198.245.60.162:9101unblockneteasemusic_1 | MITM > 198.245.60.162:9101unblockneteasemusic_1 | MITM > 198.245.60.162:9101unblockneteasemusic_1 | MITM > 198.245.60.162:9101unblockneteasemusic_1 | MITM > 198.245.60.162:9101unblockneteasemusic_1 | MITM > 198.245.60.162:9101unblockneteasemusic_1 | MITM > 198.245.60.162:9101unblockneteasemusic_1 | MITM > 198.245.60.162:9101unblockneteasemusic_1 | MITM > 5.188.210.13unblockneteasemusic_1 | MITM > 121.4.113.98:8888unblockneteasemusic_1 | MITM > 121.4.113.98:8888unblockneteasemusic_1 | MITM > 121.4.113.98:8888unblockneteasemusic_1 | MITM > www.dqwfwl.cnunblockneteasemusic_1 | MITM > www.dqwfwl.cnunblockneteasemusic_1 | MITM > www.dqwfwl.cnunblockneteasemusic_1 | MITM > www.dqwfwl.cn
复制代码
我搜第二个ip, 看到这个结果
5.188.210.13 reported as spam and brute force attacks3223 websites attacked, discovered Jul 24, 2018, last activity May 03, 2021 11:02:38.
1 brute force attacks, last activity Nov 16, 2018 18:57:45. |
|