2024-01-16T11:07:53 Notice suricata [100103] <Notice> -- all 16 packet processing threads, 4 management threads initialized, engine started. 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'exe.no.referer' is checked but not set. Checked in 2020500 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.pdf.in.http' is checked but not set. Checked in 2017150 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'HTTP.UncompressedFlash' is checked but not set. Checked in 2023313 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ETPRO.RTF' is checked but not set. Checked in 2020700 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.WinHttpRequest' is checked but not set. Checked in 2019823 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.BonitaDefaultCreds' is checked but not set. Checked in 2036817 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'dcerpc.rpcnetlogon' is checked but not set. Checked in 2030870 and 6 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.gocd.auth' is checked but not set. Checked in 2034333 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.WebDAVURL' is checked but not set. Checked in 2049320 and 2 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.generictelegram' is checked but not set. Checked in 2045614 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.tcpraw.png' is checked but not set. Checked in 2035477 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'min.gethttp' is checked but not set. Checked in 2023711 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.autoit.ua' is checked but not set. Checked in 2019165 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.http.javaclient' is checked but not set. Checked in 2017181 and 5 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.Socks5.OnionReq' is checked but not set. Checked in 2027704 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.smb.binary' is checked but not set. Checked in 2027402 and 4 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.IE7.NoRef.NoCookie' is checked but not set. Checked in 2023671 and 9 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.armwget' is checked but not set. Checked in 2024242 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.http.binary' is checked but not set. Checked in 2023741 and 4 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.MS.WinHttpRequest.no.exe.request' is checked but not set. Checked in 2022653 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.MCOFF' is checked but not set. Checked in 2022303 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.MS.XMLHTTP.no.exe.request' is checked but not set. Checked in 2022053 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.MS.XMLHTTP.ip.request' is checked but not set. Checked in 2022050 and 1 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.wininet.UA' is checked but not set. Checked in 2021312 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.MSSQL' is checked but not set. Checked in 2020569 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.DocVBAProject' is checked but not set. Checked in 2020170 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.ELFDownload' is checked but not set. Checked in 2019896 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.http.javaclient.vulnerable' is checked but not set. Checked in 2013036 and 0 other sigs 2024-01-16T11:07:10 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'is_proto_irc' is checked but not set. Checked in 2002029 and 4 other sigs 2024-01-16T11:06:52 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_DEPRECATED(203)] - Found deprecated eve-log.alert app-layer flag "tls", enabling metadata.app-layer 2024-01-16T11:06:52 Warning suricata [100103] <Warning> -- [ERRCODE: SC_WARN_DEPRECATED(203)] - Found deprecated eve-log.alert app-layer flag "http", enabling metadata.app-layer 2024-01-16T11:06:52 Warning suricata [143203] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol http2 enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details. 2024-01-16T11:06:52 Warning suricata [143203] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol http2 enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details. 2024-01-16T11:06:52 Warning suricata [143203] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol rdp enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details. 2024-01-16T11:06:52 Warning suricata [143203] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol mqtt enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details. 2024-01-16T11:06:52 Warning suricata [143203] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol rfb enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details. 2024-01-16T11:06:52 Warning suricata [143203] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol sip enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details. 2024-01-16T11:06:51 Notice suricata [143203] <Notice> -- This is Suricata version 6.0.15 RELEASE running in SYSTEM mode 2024-01-16T11:06:47 Notice suricata [100103] <Notice> -- Signal Received. Stopping engine.
2029985 drop emerging-exploit.rules attempted-admin ET EXPLOIT IBM Data Risk Manager Remote Code Execution via NMAP Scan 2000537 alert emerging-scan.rules attempted-recon ET SCAN NMAP -sS window 2048 2000536 alert emerging-scan.rules attempted-recon ET SCAN NMAP -sO 2000538 alert emerging-scan.rules attempted-recon ET SCAN NMAP -sA (1) 2000540 alert emerging-scan.rules attempted-recon ET SCAN NMAP -sA (2) 2000543 alert emerging-scan.rules attempted-recon ET SCAN NMAP -f -sF 2000544 alert emerging-scan.rules attempted-recon ET SCAN NMAP -f -sN 2000546 alert emerging-scan.rules attempted-recon ET SCAN NMAP -f -sX 2100469 alert emerging-scan.rules attempted-recon GPL SCAN PING NMAP 2100628 alert emerging-scan.rules attempted-recon GPL SCAN nmap TCP 2101228 alert emerging-scan.rules attempted-recon GPL SCAN nmap XMAS 2100629 alert emerging-scan.rules attempted-recon GPL SCAN nmap fingerprint attempt 2009582 alert emerging-scan.rules attempted-recon ET SCAN NMAP -sS window 1024 2009583 alert emerging-scan.rules attempted-recon ET SCAN NMAP -sS window 3072 2009584 alert emerging-scan.rules attempted-recon ET SCAN NMAP -sS window 4096 2018317 drop emerging-scan.rules attempted-recon ET SCAN NMAP SIP Version Detect OPTIONS Scan 2018318 drop emerging-scan.rules attempted-recon ET SCAN NMAP SIP Version Detection Script Activity 2000545 alert emerging-scan.rules attempted-recon ET SCAN NMAP -f -sV 2018489 drop emerging-scan.rules attempted-recon ET SCAN NMAP OS Detection Probe 2013778 drop emerging-scan.rules web-application-attack ET SCAN NMAP SQL Spider Scan 2009358 drop emerging-scan.rules web-application-attack ET SCAN Nmap Scripting Engine User-Agent Detected (Nmap Scripting Engine) 2009359 drop emerging-scan.rules web-application-attack ET SCAN Nmap Scripting Engine User-Agent Detected (Nmap NSE) 2024364 drop emerging-scan.rules web-application-attack ET SCAN Possible Nmap User-Agent Observed 2021024 drop emerging-scan.rules attempted-recon ET SCAN Nmap NSE Heartbleed Response 2021023 drop emerging-scan.rules attempted-recon ET SCAN Nmap NSE Heartbleed Request 2036252 drop emerging-scan.rules network-scan ET SCAN RDP Connection Attempt from Nmap
OPNsense 23.7.11-amd64FreeBSD 13.2-RELEASE-p7OpenSSL 1.1.1wCPU type: Intel(R) Celeron(R) CPU J3160 @ 1.60GHz (4 cores, 4 threads)CPU usage: Load average 1.52, 1.25, 1.23
2024-01-16T11:26:10.613038+0200 2010936 blocked LAN 192.168.1.156 49622 192.168.1.1 1521 ET SCAN Suspicious inbound to Oracle SQL port 1521 2024-01-16T11:26:10.613038+0200 2010936 blocked LAN 192.168.1.156 49622 192.168.1.1 1521 ET SCAN Suspicious inbound to Oracle SQL port 1521 2024-01-16T11:26:10.275462+0200 2002910 blocked LAN 192.168.1.156 49622 192.168.1.1 5801 ET SCAN Potential VNC Scan 5800-5820 2024-01-16T11:26:10.178190+0200 2002911 blocked LAN 192.168.1.156 49622 192.168.1.1 5906 ET SCAN Potential VNC Scan 5900-5920 2024-01-16T11:26:10.163759+0200 2002910 blocked LAN 192.168.1.156 49621 192.168.1.1 5801 ET SCAN Potential VNC Scan 5800-5820
2024-01-19T11:36:09.999708+0200 2009582 allowed WAN xxx.148.72.192 47613 91.155.xxx 3389 ET SCAN NMAP -sS window 1024 2024-01-19T11:36:02.220004+0200 2500010 allowed WAN xxx.19.24.23 53734 91.155.xxx 8080 ET COMPROMISED Known Compromised or Hostile Host Traffic group 6 2024-01-19T11:34:47.667573+0200 2009582 allowed WAN xxx.94.95.226 56852 91.155.xxx 8080 ET SCAN NMAP -sS window 1024 2024-01-19T11:33:40.068103+0200 2009582 allowed WAN xxx.94.95.226 56808 91.155.xxx 8443 ET SCAN NMAP -sS window 1024 2024-01-19T11:33:40.068103+0200 2400003 allowed WAN xxx.94.95.226 56808 91.155.xxx 8443 ET DROP Spamhaus DROP Listed Traffic Inbound group 4
alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET SCAN NMAP -sS window 1024"; fragbits:!D; dsize:0; flags:S,12; ack:0; window:1024; threshold: type both, track by_dst, count 1, seconds 60; reference:url,doc.emergingthreats.net/2009582; classtype:attempted-recon; sid:2009582; rev:3; metadata:created_at 2010_07_30, updated_at 2010_07_30;)