Ralf Hildebrandt wrote:
* Ralf Hildebrandt <[email protected]>:
I'm seeing a continuous stream of POST requests to Akamai IP space:

10.47.88.65 266040 POST http://87.248.217.42/idle/OhTmbD8nS1BmeTWY/13
10.47.88.65 267796 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/14
10.47.88.65 128319 POST http://87.248.217.42/idle/OhTmbD8nS1BmeTWY/14
10.47.88.65 256728 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/15
10.47.88.65 207705 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/23
10.47.88.65 126901 POST http://87.248.217.42/idle/OhTmbD8nS1BmeTWY/24
10.47.88.65 156025 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/28
10.47.88.65 137205 POST http://87.248.217.42/idle/OhTmbD8nS1BmeTWY/29
10.47.88.65 239690 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/33

What IS this? I know about akamai, but POST? Usually they're
distributing DOWNLOADS, not uploads. What is going on here?

I'm seeing this from different IPs in my net.


Could be a lot of things, from some new online game to a virus.
Can you grab a tcpdump of some of these requests?

Amos
--
Please be using
  Current Stable Squid 2.7.STABLE7 or 3.0.STABLE21
  Current Beta Squid 3.1.0.15

Reply via email to