Skip to content

Instantly share code, notes, and snippets.

@dhurley14
Created May 25, 2016 03:08
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save dhurley14/f798d2105bb68ac94a70d24385e9b477 to your computer and use it in GitHub Desktop.
Save dhurley14/f798d2105bb68ac94a70d24385e9b477 to your computer and use it in GitHub Desktop.
pi@raspberrypi:/var/log/maltrail $ tail 2016-05-18.log 2016-05-19.log 2016-05-20.log 2016-05-21.log 2016-05-22.log 2016-05-23.log 2016-05-24.log 2016-05-25.log
==> 2016-05-18.log <==
"2016-05-18 23:47:51.125602" raspberrypi 192.168.1.5 35579 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-18 23:49:59.424015" raspberrypi 192.168.1.5 - 136.161.101.53 - ICMP IP 136.161.101.53 "sinkhole conficker (malware)" (static)
==> 2016-05-19.log <==
"2016-05-19 10:26:19.485956" raspberrypi 192.168.1.5 39074 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-19 11:59:51.032876" raspberrypi 192.168.1.5 39075 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-19 13:25:15.583751" raspberrypi 192.168.1.5 39076 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-19 15:10:59.114896" raspberrypi 192.168.1.5 39077 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-19 16:18:05.116327" raspberrypi 192.168.1.5 35591 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-19 17:53:39.338610" raspberrypi 192.168.1.5 56167 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-19 18:54:39.912436" raspberrypi 192.168.1.5 56168 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-19 20:28:11.449440" raspberrypi 192.168.1.5 56169 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-19 21:59:41.135603" raspberrypi 192.168.1.5 39082 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-19 23:49:29.758989" raspberrypi 192.168.1.5 39087 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
==> 2016-05-20.log <==
"2016-05-20 07:40:12.254745" raspberrypi 192.168.1.5 39092 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-20 09:35:05.818209" raspberrypi 192.168.1.5 56181 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-20 11:44:12.471937" raspberrypi 192.168.1.5 39094 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-20 13:11:39.005745" raspberrypi 192.168.1.5 56183 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-20 14:37:02.486539" raspberrypi 192.168.1.5 35609 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-20 16:42:05.693349" raspberrypi 192.168.1.5 35610 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-20 18:11:33.841289" raspberrypi 192.168.1.5 39098 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-20 20:49:08.840117" raspberrypi 192.168.1.5 56187 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-20 21:54:12.351817" raspberrypi 192.168.1.5 35613 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-20 23:23:40.508039" raspberrypi 192.168.1.5 35614 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
==> 2016-05-21.log <==
"2016-05-21 09:00:07.371013" raspberrypi 192.168.1.5 39113 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-21 10:06:12.102184" raspberrypi 192.168.1.5 56202 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-21 11:48:53.817372" raspberrypi 192.168.1.5 35628 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-21 13:41:44.217674" raspberrypi 192.168.1.5 35629 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-21 15:20:21.460947" raspberrypi 192.168.1.5 39117 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-21 17:33:32.079758" raspberrypi 192.168.1.5 35631 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-21 19:26:23.401780" raspberrypi 192.168.1.5 39119 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-21 20:54:51.007005" raspberrypi 192.168.1.5 35633 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-21 22:36:30.193430" raspberrypi 192.168.1.5 35634 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-21 23:57:50.329155" raspberrypi 192.168.1.5 56212 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
==> 2016-05-22.log <==
"2016-05-22 16:54:24.964482" raspberrypi 192.168.1.5 39137 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-22 16:54:24.974135" raspberrypi 192.168.1.5 35651 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-22 16:54:24.962455" raspberrypi 192.168.1.5 56224 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-22 17:43:19.018508" raspberrypi 192.168.1.5 35652 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-22 19:38:12.302670" raspberrypi 192.168.1.5 56228 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-22 21:13:12.076544" raspberrypi 192.168.1.5 56229 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-22 21:13:44.153131" raspberrypi 192.168.1.5 39143 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-22 21:13:44.150710" raspberrypi 192.168.1.5 35655 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-22 22:51:26.755911" raspberrypi 192.168.1.5 39146 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-22 22:51:26.757747" raspberrypi 192.168.1.5 35660 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
==> 2016-05-23.log <==
"2016-05-23 09:51:11.806505" raspberrypi 192.168.1.5 35670 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-23 11:12:31.992299" raspberrypi 192.168.1.5 35671 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-23 12:14:32.247054" raspberrypi 192.168.1.5 56247 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-23 13:18:35.892881" raspberrypi 192.168.1.5 35673 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-23 15:29:44.063431" raspberrypi 192.168.1.5 35674 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-23 17:43:56.222970" raspberrypi 192.168.1.5 56250 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-23 19:22:33.699936" raspberrypi 192.168.1.5 39163 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-23 20:52:01.055207" raspberrypi 192.168.1.5 39164 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-23 21:50:59.660221" raspberrypi 192.168.1.5 35678 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-23 23:33:40.886452" raspberrypi 192.168.1.5 56254 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
==> 2016-05-24.log <==
"2016-05-24 09:30:28.001615" raspberrypi 192.168.1.5 56261 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-24 10:51:47.589910" raspberrypi 192.168.1.5 39174 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-24 12:42:36.207583" raspberrypi 192.168.1.5 35688 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-24 14:00:53.402776" raspberrypi 192.168.1.5 35689 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-24 15:15:06.684227" raspberrypi 192.168.1.5 39177 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-24 17:12:01.952070" raspberrypi 192.168.1.5 35691 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-24 18:45:33.167663" raspberrypi 192.168.1.5 35692 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-24 20:43:29.362391" raspberrypi 192.168.1.5 56268 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-24 22:31:15.860403" raspberrypi 192.168.1.5 39181 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-24 23:47:30.393034" raspberrypi 192.168.1.5 56272 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
==> 2016-05-25.log <==
"2016-05-25 01:28:09.133112" raspberrypi 192.168.1.5 56273 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-25 02:31:56.433744" raspberrypi 192.168.1.5 39188 178.63.9.165 443 TCP IP 178.63.9.165 "tor exit node (suspicious)" blutmagie.de
"2016-05-25 02:31:56.431436" raspberrypi 192.168.1.5 35700 128.208.2.233 9001 TCP IP 128.208.2.233 "tor exit node (suspicious)" blutmagie.de
"2016-05-25 02:31:56.429470" raspberrypi 192.168.1.5 56274 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-25 02:42:14.538911" raspberrypi 192.168.1.5 56277 62.210.92.11 9001 TCP IP 62.210.92.11 "tor exit node (suspicious)" blutmagie.de
"2016-05-25 02:53:08.504835" raspberrypi 192.168.1.5 - 136.161.101.53 - ICMP IP 136.161.101.53 "sinkhole conficker (malware)" (static)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment