Skip to content

Instantly share code, notes, and snippets.

@liam-stevenson
Created December 31, 2020 15:50
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save liam-stevenson/da801fc638d138e994333d60f5c73773 to your computer and use it in GitHub Desktop.
Save liam-stevenson/da801fc638d138e994333d60f5c73773 to your computer and use it in GitHub Desktop.
Dec 03 31 - 15:43:23 192.168.250.1 date=2016-08-28 time=23:36:34 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.227.189 srcport=32020 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=768688 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=47013 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:23 192.168.250.1 date=2016-08-13 time=04:44:20 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.225.15 srcport=123 srcintf="internal5" dstip=69.167.160.102 dstport=123 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=803953 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=123 service="NTP" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:23 192.168.250.1 date=2016-08-28 time=23:36:34 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=185.56.82.14 srcport=64932 srcintf="wan1" dstip=71.39.18.124 dstport=445 dstintf="wan1" sessionid=741815 proto=6 action=deny policyid=0 dstcountry="United States" srccountry="Netherlands" trandisp=noop service="SMB" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel=high
Dec 03 31 - 15:43:23 192.168.250.1 date=2016-08-13 time=23:56:27 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.229.239 srcport=9109 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=769092 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=37928 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:23 192.168.250.1 date=2016-08-28 time=23:36:33 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.230.147 srcport=34458 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=735542 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=23903 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:24 192.168.250.1 date=2016-08-28 time=23:36:32 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.224.233 srcport=3631 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=833066 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=64047 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:24 192.168.250.1 date=2016-08-28 time=23:36:32 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=192.168.231.3 srcport=17628 srcintf="internal3" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=52cb59e8-a672-51e4-caa9-bab04c998d3a sessionid=729212 proto=17 action=accept policyid=10 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=34356 service="DNS" appid=16195 app="DNS" appcat="Network.Service" apprisk=elevated applist="Honeypot-Access" appact=detected duration=180 sentbyte=53 rcvdbyte=128 sentpkt=1 rcvdpkt=1
Dec 03 31 - 15:43:24 192.168.250.1 date=2016-08-21 time=23:42:38 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.227.24 srcport=6988 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=833832 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=6988 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:24 192.168.250.1 date=2016-08-28 time=23:36:32 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.230.226 srcport=40476 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=735952 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=34465 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:24 192.168.250.1 date=2016-08-22 time=02:06:57 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=181.44.32.2 srcport=49996 srcintf="wan1" dstip=71.39.18.123 dstport=23 dstintf="wan1" sessionid=768939 proto=6 action=deny policyid=0 dstcountry="United States" srccountry="Argentina" trandisp=noop service="TELNET" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel=high
Dec 03 31 - 15:43:25 192.168.250.1 date=2016-08-28 time=23:36:31 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=103.23.135.30 srcport=62690 srcintf="wan1" dstip=71.39.18.124 dstport=23 dstintf="wan1" sessionid=733257 proto=6 action=deny policyid=0 dstcountry="United States" srccountry="Cambodia" trandisp=noop service="TELNET" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel=high
Dec 03 31 - 15:43:25 192.168.250.1 date=2016-08-12 time=13:53:05 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.225.96 srcport=45158 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=844155 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=18496 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:25 192.168.250.1 date=2016-08-28 time=23:36:29 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.225.48 srcport=19078 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=852190 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=47632 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:25 192.168.250.1 date=2016-08-18 time=23:05:01 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.225.237 srcport=48525 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=804619 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=51624 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:25 192.168.250.1 date=2016-08-28 time=23:36:29 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=218.205.129.146 srcport=58296 srcintf="wan1" dstip=71.39.18.121 dstport=23 dstintf="wan1" sessionid=763463 proto=6 action=deny policyid=0 dstcountry="United States" srccountry="China" trandisp=noop service="TELNET" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel=high
Dec 03 31 - 15:43:26 192.168.250.1 date=2016-08-07 time=16:33:46 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.224.222 srcport=38335 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=810793 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=57788 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:26 192.168.250.1 date=2016-08-28 time=23:36:29 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.225.223 srcport=45007 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=728261 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=23926 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:26 192.168.250.1 date=2016-08-28 time=23:36:29 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.228.148 srcport=2149 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=843646 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=51097 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:26 192.168.250.1 date=2016-08-22 time=09:30:29 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.228.164 srcport=38724 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=732638 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=42429 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:26 192.168.250.1 date=2016-08-28 time=23:36:29 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.231.57 srcport=40782 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=801444 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=62591 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:27 192.168.250.1 date=2016-08-12 time=12:45:40 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.230.236 srcport=7454 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=800257 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=7454 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:27 192.168.250.1 date=2016-08-28 time=23:36:27 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.226.4 srcport=11597 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=728564 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=54204 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:27 192.168.250.1 date=2016-08-05 time=08:15:08 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.228.174 srcport=7346 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=809801 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=34492 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:27 192.168.250.1 date=2016-08-28 time=23:36:27 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.229.95 srcport=58628 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=842264 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=31095 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:27 192.168.250.1 date=2016-08-18 time=10:07:50 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=95.37.140.152 srcport=1329 srcintf="wan1" dstip=71.39.18.121 dstport=445 dstintf="wan1" sessionid=816216 proto=6 action=deny policyid=0 dstcountry="United States" srccountry="Russian Federation" trandisp=noop service="SMB" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel=high
Dec 03 31 - 15:43:28 192.168.250.1 date=2016-08-28 time=23:36:26 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.229.181 srcport=4310 srcintf="internal5" dstip=8.8.4.4 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=832917 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=64726 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:28 192.168.250.1 date=2016-08-23 time=16:27:27 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=113.163.19.163 srcport=28054 srcintf="wan1" dstip=71.39.18.122 dstport=22 dstintf="wan1" sessionid=809962 proto=6 action=deny policyid=0 dstcountry="United States" srccountry="Vietnam" trandisp=noop service="SSH" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel=high
Dec 03 31 - 15:43:28 192.168.250.1 date=2016-08-28 time=23:36:26 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.228.2 srcport=2282 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=848500 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=62698 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Dec 03 31 - 15:43:28 192.168.250.1 date=2016-08-24 time=17:33:36 devname=gotham-fortigate devid=FGT60D4614044725 logid=0000000015 type=traffic subtype=forward level=notice vd=root srcip=192.168.230.7 srcport=31455 srcintf="internal5" dstip=8.8.8.8 dstport=53 dstintf="wan1" poluuid=b0031368-5022-51e4-7b44-081eb5c90956 sessionid=851275 proto=17 action=start policyid=3 dstcountry="United States" srccountry="Reserved" trandisp=snat transip=71.39.18.126 transport=51489 service="DNS" duration=0 sentbyte=0 rcvdbyte=0 appcat="unscanned"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment