I did a reverse name lookup, and they are all in the amazon cloud:

   54.208.254.185           name =
   ec2-54-208-254-185.compute-1.amazonaws.com
   54.174.193.49            name =
   ec2-54-174-193-49.compute-1.amazonaws.com
   54.173.255.111           name =
   ec2-54-173-255-111.compute-1.amazonaws.com


bp
<part15sbs{at}gmail{dot}com>

On 4/13/2015 10:37 AM, Ken Hohhof wrote:
What port numbers?

I have seen this with an infected router. The traffic was in and back out to Amazon cloud, as if it had been taken over for a proxy or something.

Something else to look for is some Costco type security camera system with a cloud DVR.


-----Original Message----- From: Bill Prince
Sent: Monday, April 13, 2015 12:22 PM
To: Motorola III
Subject: [AFMUG] Amazon EC2


I was trouble shooting a problem on a connection this morning, and found
that the client had three streams running to EC2 in the Amazon AWS
cloud. It has been running for months, at a more-or-less constant
upstream rate of about 300 Kbps per stream (all three streams together
are less than 1 Mbps, but they are all constant, running 24x7 for at
least the last 8 months).

Is this a hijack of some sort? This particular customer is not
sophisticated, and I can not imagine what sort of compute resource he
might require. He barely knows how to boot up his computer.



Reply via email to