to Dalibor Toman: No umět toho víc, asi bych se do toho pustil, ale takto můžu poskytnout pouze ty požadované IP. Ostatně, když si nastražíš na veřejku mikrotik a zafiltruješ si jen port 8291, v tu ránu jich máš spousty. Třeba 178.77.209.53. Vsadil bych se, že tam je mikrotik a to napadený anebo je už napadený ten můj. Každopádně, kdo se víc orientuje, může nasadit odchyt paketů a je to (asi) jasné. mpcz, 18.5.2018
p.s. našel jsem správce nadřízené sítě útočícího stroje, je tam 6.37, ale je to se vší pravděpodobností zavirované. Už to zablokoval, takže víc se zkoumat nedá. Provozovatel je NO IT.
a v logu téměř každého MKT na veřejce najdeš další info, např.
apr/28 15 system,error,critical login failure for user test from 155.94.65.20 via ftp
apr/28 15 system,error,critical login failure for user read from 155.94.65.20 via ftp
apr/28 15 system,error,critical login failure for user default from 155.94.65.20 via ftp
apr/28 15 system,error,critical login failure for user read from 155.94.65.20 via ftp
apr/30 19 system,error,critical login failure for user anonymous from 91.121.116.128 via ftp
may/02 08 system,error,critical login failure for user www-data from 157.33.116.171 via ftp
may/03 19 system,error,critical login failure for user anonymous from 75.80.182.128 via ftp
may/04 03 system,error,critical login failure for user anonymous from 125.212.217.214 via ftp
may/04 10 system,error,critical login failure for user admin from 122.170.41.119 via ftp
may/05 04 system,error,critical login failure for user admin from 172.245.13.10 via web
may/05 04 system,error,critical login failure for user admin from 172.245.13.10 via web
may/05 04 system,error,critical login failure for user admin from 172.245.13.10 via web
may/05 04 system,error,critical login failure for user admin from 172.245.13.10 via web
may/05 04 system,error,critical login failure for user admin from 172.245.13.10 via web
may/05 15 system,error,critical login failure for user anonymous from 109.64.64.72 via ftp
may/05 18 system,error,critical login failure for user admin from 213.183.51.130 via web
may/17 08 warning denied winbox/dude connect from 185.77.128.128
may/11 19 warning denied winbox/dude connect from 117.50.7.159
may/11 19 warning denied winbox/dude connect from 117.50.7.159
may/11 19 warning denied winbox/dude connect from 117.50.7.159
may/11 19 warning denied winbox/dude connect from 117.50.7.159
may/11 19 warning denied winbox/dude connect from 117.50.7.159
may/12 00 warning denied winbox/dude connect from 31.148.219.52
may/08 08 system,error,critical login failure for user admin from 37.24.220.129 via web
may/08 08 system,error,critical login failure for user admin from 37.24.220.129 via web
may/08 08 system,error,critical login failure for user admin from 37.24.220.129 via web
may/08 08 system,error,critical login failure for user admin from 37.24.220.129 via web
may/08 08 system,error,critical login failure for user admin from 37.24.220.129 via web
may/06 05 system,error,critical login failure for user anonymous from 71.6.146.186 via ftp
may/06 09 system,error,critical login failure for user root from 157.32.78.205 via ftp
may/06 23 system,error,critical login failure for user anonymous from 71.6.167.142 via ftp
may/07 10 system,error,critical login failure for user www-data from 157.49.14.240 via ftp
apr/28 09 system,error,critical login failure for user anonymous from 51.38.12.13 via ftp
apr/28 11 system,error,critical login failure for user user from 117.222.46.220 via ftp
apr/28 15 system,error,critical login failure for user ftp from 155.94.65.20 via ftp
apr/28 15 system,error,critical login failure for user anyone from 155.94.65.20 via ftp
apr/28 15 system,error,critical login failure for user user from 155.94.65.20 via ftp
apr/28 15 system,error,critical login failure for user test from 155.94.65.20 via ftp
apr/28 15 system,error,critical login failure for user user from 155.94.65.20 via ftp
may/05 18 system,error,critical login failure for user admin from 213.183.51.130 via web
may/05 18 system,error,critical login failure for user admin from 213.183.51.130 via web
may/05 18 system,error,critical login failure for user admin from 213.183.51.130 via web
may/05 18 system,error,critical login failure for user admin from 213.183.51.130 via web