Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Windows 10 machines constantly pinging Israel IPs

    pfBlockerNG
    2
    2
    199
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      azdeltawye last edited by azdeltawye

      Hello,
      I recently enabled IPv4 blocking on pfBlockerNG-devel using the following PRI1 feeds:
      Abuse_Feodo_C2
      ET_Block
      ET_Comp
      Talos_BL

      Since doing this I checked the firewall logs and have noticed both of my Windows 10 computers continuously sending ICMP requests every minute to a group of IPs ranging from 185.77.248.10 - 185.77.248.89..

      Doing a search on these IP addresses reveals very little other than the GeoIP location of Israel.

      Does Microsoft have servers in Israel??

      Thanks!

      NogBadTheBad 1 Reply Last reply Reply Quote 0
      • NogBadTheBad
        NogBadTheBad @azdeltawye last edited by

        @azdeltawye said in Windows 10 machines constantly pinging Isreal IPs:

        185.77.248.89

        AS details for AS58018 :-

        aut-num: AS58018
        as-name: NETSTYLE2
        org: ORG-NAL9-RIPE
        import: from AS43945 accept ANY
        export: to AS43945 announce AS-NETSTYLE
        admin-c: DUMY-RIPE
        tech-c: DUMY-RIPE
        member-of: AS-NETSTYLE
        status: ASSIGNED
        mnt-by: RIPE-NCC-END-MNT
        mnt-by: EC42500-MNT
        created: 2017-01-02T14:57:40Z
        last-modified: 2018-09-04T11:56:16Z
        source: RIPE
        remarks: ****************************
        remarks: * THIS OBJECT IS MODIFIED
        remarks: * Please note that all data that is generally regarded as personal
        remarks: * data has been removed from this object.
        remarks: * To view the original object, please query the RIPE Database at:
        remarks: * http://www.ripe.net/whois
        remarks: ****************************

        IPv4 subnets for AS58018 :-

        185.77.248.0/24

        IPv6 subnets for AS58018 :-

        2a00:55a0:3::/48

        Wednesday, 9 December 2020 at 21:39:06 Greenwich Mean Time

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • First post
          Last post