13 security vendors flagged this IP address / Active Treat Showing During Windows 11 Updates
-
Snort IPS/IDS is catching something different today. I thought I would share this flagged invasive actor with the community.
Has anyone else seen this IP hit your firewalls during Windows 11 updates?
45.143.9.106
AS 3999045 (DEDIOUTLET-NETWORKS)
(This was flagged by 13 different security providers)The IP block is out of Lithuania? Maybe this has to do with what is occuring in the former Zaire with what is being broadcast over worldband radio signal the last couple weeks, anyone hear that radio station last week? Maybe it was a replay of old radio signals? Anyway enough of the rabbit hole.
I don't understand why this is flagged and showing up only during Windows 11 updates that's what throws me off here. Something is off with this IP address
Anyone else notice anything or maybe run a Wireshark on it?