Jan. 21, 2022, 5:32 a.m. | /u/keeny-fn-pawers

Computer Forensics www.reddit.com

While investigating a remote intrusion warning I noticed http traffic from two separate devices communicating with private IP subnet ranges that do not belong to any of our routers, or other devices. All of the traffic are to port 80.

Example IPs include:

10.50.60.15

10.80.80.112

209.54.181.102

All the above are reserved private ranges and the aforementioned traffic was observed on two different routers, but using the same Verizon modem. Anyone seen this before, or can explain? There are no VPNs …

computerforensics traffic

Cyber Security Engineer I

@ Fortress Security Risk Management | Cleveland, OH, United States

Senior DevSecOps Engineer

@ Wisk Aero | Remote United States

Vulnerable Adult Investigator - Vice President

@ JPMorgan Chase & Co. | Chicago, IL, United States

Consultant Réseaux IT Digital Impulse - H/F

@ Talan | Paris, France

DevSecOps Engineer (Onsite)

@ Accenture Federal Services | Arlington, VA

Senior Security Engineer

@ Minitab | State College, Pennsylvania, United States