嘟嘟社区

[疑问] 安装的UnblockNeteaseMusic一直访问奇怪的ip和网址


本帖最后由 Alita 于 2022-2-5 11:49 编辑

用的原作者的 https://github.com/nondanee/UnblockNeteaseMusic

结果发现一直访问奇怪的ip和网址, 这是被植入后门了?
装在另一台vps也是这个情况

  1. unblockneteasemusic_1  | MITM > 198.245.60.162:9101
  2. unblockneteasemusic_1  | MITM > 198.245.60.162:9101
  3. unblockneteasemusic_1  | MITM > 198.245.60.162:9101
  4. unblockneteasemusic_1  | MITM > 198.245.60.162:9101
  5. unblockneteasemusic_1  | MITM > 198.245.60.162:9101
  6. unblockneteasemusic_1  | MITM > 198.245.60.162:9101
  7. unblockneteasemusic_1  | MITM > 198.245.60.162:9101
  8. unblockneteasemusic_1  | MITM > 198.245.60.162:9101
  9. unblockneteasemusic_1  | MITM > 198.245.60.162:9101
  10. unblockneteasemusic_1  | MITM > 5.188.210.13
  11. unblockneteasemusic_1  | MITM > 121.4.113.98:8888
  12. unblockneteasemusic_1  | MITM > 121.4.113.98:8888
  13. unblockneteasemusic_1  | MITM > 121.4.113.98:8888
  14. unblockneteasemusic_1  | MITM > www.dqwfwl.cn
  15. unblockneteasemusic_1  | MITM > www.dqwfwl.cn
  16. unblockneteasemusic_1  | MITM > www.dqwfwl.cn
  17. unblockneteasemusic_1  | MITM > www.dqwfwl.cn

复制代码

我搜第二个ip, 看到这个结果

5.188.210.13 reported as spam and brute force attacks3223 websites attacked, discovered Jul 24, 2018, last activity May 03, 2021 11:02:38.
1 brute force attacks, last activity Nov 16, 2018 18:57:45.

是不是被别人扫到了

海苔 发表于 2022-2-5 11:40
是不是被别人扫到了

有这么快吗
我换另一台机器也是这个情况