I did a reverse name lookup, and they are all in the amazon cloud:
54.208.254.185 name =
ec2-54-208-254-185.compute-1.amazonaws.com
54.174.193.49 name =
ec2-54-174-193-49.compute-1.amazonaws.com
54.173.255.111 name =
ec2-54-173-255-111.compute-1.amazonaws.com
bp
<part15sbs{at}gmail{dot}com>
On 4/13/2015 10:37 AM, Ken Hohhof wrote:
What port numbers?
I have seen this with an infected router. The traffic was in and back
out to Amazon cloud, as if it had been taken over for a proxy or
something.
Something else to look for is some Costco type security camera system
with a cloud DVR.
-----Original Message----- From: Bill Prince
Sent: Monday, April 13, 2015 12:22 PM
To: Motorola III
Subject: [AFMUG] Amazon EC2
I was trouble shooting a problem on a connection this morning, and found
that the client had three streams running to EC2 in the Amazon AWS
cloud. It has been running for months, at a more-or-less constant
upstream rate of about 300 Kbps per stream (all three streams together
are less than 1 Mbps, but they are all constant, running 24x7 for at
least the last 8 months).
Is this a hijack of some sort? This particular customer is not
sophisticated, and I can not imagine what sort of compute resource he
might require. He barely knows how to boot up his computer.