Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Odd IRC traffic - pleaes review

Howdy all.

I've seen some crazy odd traffic being reported by the ASG box as IRC traffic, but I have IRC clients blocked and none running on the machine in question as the source. Not sure what to make of it. I have scanned for viruses and spyware and found nothing. There are days and days of dropped lines in the log files between the same two addresses.

The dstip is a web server. 
The srcip is one of my computers.

/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:42:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1577" dstport="30235" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:42:57 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1581" dstport="45955" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:44:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1585" dstport="42568" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:44:27 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1589" dstport="43839" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:45:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1593" dstport="45973" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:45:57 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1597" dstport="34016" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:47:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1601" dstport="33410" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:47:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1605" dstport="40146" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:48:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1609" dstport="39734" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:48:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1613" dstport="48088" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:50:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1617" dstport="37128" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:50:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1621" dstport="33875" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:51:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1625" dstport="42650" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:51:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1629" dstport="34460" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:53:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1633" dstport="44023" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:53:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1637" dstport="40826" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:54:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1641" dstport="30520" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:54:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1645" dstport="39976" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:56:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1649" dstport="42274" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:56:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1653" dstport="48404" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:57:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1657" dstport="42959" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:57:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1661" dstport="49305" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:59:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1665" dstport="48912" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-03:59:28 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1669" dstport="30449" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-04:00:31 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1673" dstport="31752" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-04:00:58 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1677" dstport="48992" tcpflags="ACK" 
/var/log/afc/2008/07/afc-2008-07-31.log.gz:2008:07:31-04:02:01 (none) ulogd[2501]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="60100" outitf="eth1" srcip="172.16.2.100" dstip="72.29.XX.XX" proto="6" length="1500" tos="0x00" prec="0x00" ttl="127" srcport="1681" dstport="44489" tcpflags="ACK"


Am I reading this correctly? Is this showing an IRC connection going out from a local computer?


This thread was automatically locked due to age.
Parents
  • Yep, it appears 172.16.2.100 is making outbound connections to 72.29.x.x using various source and destionation ports.

    If this is a Windows computer you could run "netstat -ano" at the command prompt, then look for 72.29.x.x in the "Foreign Address" column. This should also give you a process ID associated with that socket. You can then look in Task Manager and find the process ID to see what exe is making the socket connection.
  • Yep, it appears 172.16.2.100 is making outbound connections to 72.29.x.x using various source and destionation ports.

    If this is a Windows computer you could run "netstat -ano" at the command prompt, then look for 72.29.x.x in the "Foreign Address" column. This should also give you a process ID associated with that socket. You can then look in Task Manager and find the process ID to see what exe is making the socket connection.


    yeah, netstat was one of the first things I tried, the issue does not show up in the logs for the last couple days. As a matter of fact it didnt show up in the daily reports either. I just stumbled on to it today when todays report had one instance of Tencent_qq. Having no idea what that is I jumped on the log files and did a search for fwrule="601 and it showed me all of these IRC 60100 connections and one 60104 connection.
  • Looks like a popular Chinese instant messaging, or spyware.

    http://en.wikipedia.org/wiki/QQ

    http://www.antispyware.com/glossary_details.php?ID=635


    I do run google talk. Not sure if I'm getting a false positive or something. The Tencent_qq connecting showed up as the ASG WAN address as the srcip to another outside ip.
  • You probably have a nat statement so when you computer sends outbound the srcip of the packet from you computer is replaced with the ASG's WAN address and then sent on to the dstip. Which is 72.29.x.x, you could do a lookup on the actual IP address and see who owns that block of IP addresses. If it is google, than google talk might make sense, and I would say it is a false positive.
  • More silliness found.

    A weird ip address, 74.23.59.182:80 just came up on another netstat -ano

    So I dropped it in a web browser and it comes up with a cable modem (I believe)...

    Very odd...

    I'm not a comcast customer as it reads and I'm not in new jersey. So I'm not sure why it would be connecting to what appears on the surface to be a concast cable modem. I suppose I need to download a different group of virus and spyware scanners... 

    Using AVG now and Spyware Doctor. Both have run full scans and found nothing but minor things like cookies.
Reply
  • More silliness found.

    A weird ip address, 74.23.59.182:80 just came up on another netstat -ano

    So I dropped it in a web browser and it comes up with a cable modem (I believe)...

    Very odd...

    I'm not a comcast customer as it reads and I'm not in new jersey. So I'm not sure why it would be connecting to what appears on the surface to be a concast cable modem. I suppose I need to download a different group of virus and spyware scanners... 

    Using AVG now and Spyware Doctor. Both have run full scans and found nothing but minor things like cookies.
Children