From a user:
Hi Mladen,
I have a disk less pc with no hard drive. I run Pure OS from cd. That pc
is connected to 4G router and its behind RATtrap firewall. During
booting of all three devices rattrap firewall blocks outgoing attempt on
port 80 to ip address in Serbia (Belgrade). The ip is 5.22.191.144. I am
not so sure that there is no virus or hacking attempt against Pure OS.
What would be your opinion about this?
Mladen:
I need more info, what 3 devices? Did you connect more than one device to the same network?
User:
There is only one pc on the network. Let me explain. Pc wich is
connected with ethernet cable to RATtrap firewall and then connected to
ethernet port on the 4G router with 4G usb modem.
During booting i ment this. I switched on the 4G router, RATtrap
firewall start to inspect what traffic goes trough it (green and blue
light start to flash) and while something is blocked red light start to
flash. The RATtrap firewall is in high protection mode.
Mladen:
So it catches that IP ony when you start your computer with PureOS? Can you try with different live GNU/Linux please (like Linux Mint)?
User:
I tried several live linux but not linux mint. I even tried TENS
military public live iso but i did not encounter on that ip address from
that country. Yes that ip was caught during booting of Pure OS. I always
check attacker ip address on the ip address lookup website to get more
info. That is all i can say.
Worth investigating.