Project

General

Profile

Bug #14054 » pfblockerng.log

Marcos M, 03/09/2023 05:33 PM

 
1
 CRON  PROCESS  START [ v3.2.0_3 ] [ 03/9/23 12:00:00 ]
2
[ Abuse_Feodo_C2_v4 ]
3
  Remote timestamp: Thu, 9 Mar 2023 17:55:03 GMT
4
  Local  timestamp: Thu, 9 Mar 2023 16:55:03 GMT	Update found
5
[ Abuse_SSLBL_v4 ]
6
  Remote timestamp: Thu, 9 Mar 2023 17:55:01 GMT
7
  Local  timestamp: Thu, 9 Mar 2023 16:55:01 GMT	Update found
8
[ CINS_army_v4 ]
9
  Remote timestamp: Thu, 9 Mar 2023 16:18:08 GMT
10
  Local  timestamp: Thu, 9 Mar 2023 15:18:11 GMT	Update found
11
[ ET_Block_v4 ]
12
  Remote timestamp: Wed, 8 Mar 2023 05:30:01 GMT
13
  Local  timestamp: Wed, 8 Mar 2023 05:30:01 GMT	Update not required
14
[ ET_Comp_v4 ] [ 03/9/23 12:00:02 ]
15
  Remote timestamp: Wed, 8 Mar 2023 22:07:08 GMT
16
  Local  timestamp: Wed, 8 Mar 2023 22:07:08 GMT	Update not required
17
[ ISC_Block_v4 ] [ 03/9/23 12:00:12 ]
18
  Remote timestamp: Thu, 9 Mar 2023 17:55:43 GMT
19
  Local  timestamp: Thu, 9 Mar 2023 16:25:32 GMT	Update found
20
[ Spamhaus_Drop_v4 ]
21
  Remote timestamp: Thu, 9 Mar 2023 10:24:16 GMT
22
  Local  timestamp: Thu, 9 Mar 2023 10:24:16 GMT	Update not required
23
[ Spamhaus_eDrop_v4 ] [ 03/9/23 12:00:14 ]
24
  Remote timestamp: Thu, 9 Mar 2023 10:32:13 GMT
25
  Local  timestamp: Thu, 9 Mar 2023 10:32:13 GMT	Update not required
26
[ Talos_BL_v4 ] [ 03/9/23 12:00:15 ]
27
  Max daily download failure attempts exceeded. Clear widget 'failed downloads' to reset.
28

    
29
[ EasyList ]
30
  Remote timestamp: Thu, 9 Mar 2023 17:20:30 GMT
31
  Local  timestamp: Thu, 9 Mar 2023 03:31:43 GMT	Update found
32
[ EasyPrivacy ]
33
  Remote timestamp: Thu, 9 Mar 2023 17:20:30 GMT
34
  Local  timestamp: Thu, 9 Mar 2023 03:31:43 GMT	Update found
35
[ StevenBlack_ADs ]
36
				( md5 feed )		. 200 OK
37
				( md5 unchanged )	Update not required
38
[ MalwareFilter ] [ 03/9/23 12:00:16 ]
39
  Remote timestamp: Thu, 9 Mar 2023 12:30:43 GMT
40
  Local  timestamp: Thu, 9 Mar 2023 00:30:50 GMT	Update found
41
[ OpenPhish ] [ 03/9/23 12:00:17 ]
42
  Remote timestamp: Thu, 9 Mar 2023 12:00:02 GMT
43
  Local  timestamp: Thu, 9 Mar 2023 00:00:02 GMT	Update found
44
[ SFS_ToxicDW ] [ 03/9/23 12:00:18 ]
45
  Remote timestamp: Thu, 9 Mar 2023 17:00:04 GMT
46
  Local  timestamp: Thu, 9 Mar 2023 05:00:04 GMT	Update found
47
 UPDATE PROCESS START [ v3.2.0_3 ] [ 03/9/23 12:00:19 ]
48

    
49
===[  DNSBL Process  ]================================================
50

    
51
 Loading DNSBL Statistics... completed
52
 Loading DNSBL SafeSearch... disabled
53
 Loading DNSBL Whitelist... completed
54

    
55
[ EasyList ]			 Downloading update .. 200 OK.
56
  ----------------------------------------------------------------------
57
  Orig.    Unique     # Dups     # White    # TOP1M    Final                
58
  ----------------------------------------------------------------------
59
  21734    21733      3          0          0          21730                
60
  ----------------------------------------------------------------------
61

    
62
[ EasyPrivacy ]			 Downloading update [ 03/9/23 12:00:21 ] .. 200 OK.
63
  Whitelist: click.redditmail.com|
64
  ----------------------------------------------------------------------
65
  Orig.    Unique     # Dups     # White    # TOP1M    Final                
66
  ----------------------------------------------------------------------
67
  16453    15306      16         1          0          15289                
68
  ----------------------------------------------------------------------
69

    
70
[ StevenBlack_ADs ]		 exists. [ 03/9/23 12:00:22 ]
71
[ MalwareFilter ]		 Downloading update [ 03/9/23 12:00:23 ] .. 200 OK.
72
  ----------------------------------------------------------------------
73
  Orig.    Unique     # Dups     # White    # TOP1M    Final                
74
  ----------------------------------------------------------------------
75
  15264    15264      485        0          0          14779                
76
  ----------------------------------------------------------------------
77

    
78
[ OpenPhish ]			 Downloading update [ 03/9/23 12:00:24 ] .. 200 OK.
79
  ----------------------------------------------------------------------
80
  Orig.    Unique     # Dups     # White    # TOP1M    Final                
81
  ----------------------------------------------------------------------
82
  496      387        1          0          0          386                  
83
  ----------------------------------------------------------------------
84

    
85
[ SFS_ToxicDW ]			 Downloading update [ 03/9/23 12:00:26 ] .. 200 OK.
86
  ----------------------------------------------------------------------
87
  Orig.    Unique     # Dups     # White    # TOP1M    Final                
88
  ----------------------------------------------------------------------
89
  43883    43882      5          0          0          43877                
90
  ----------------------------------------------------------------------
91

    
92
[ WindowsSpyBlocker ]		 exists. [ 03/9/23 12:00:28 ]
93
------------------------------------------------------------------------
94
Assembling DNSBL database...... completed [ 03/9/23 12:00:29 ]
95
TLD:
96
TLD analysis... completed [ 03/9/23 12:00:32 ]
97
TLD finalize...
98
 ----------------------------------------
99
 Original    Matches    Removed    Final     
100
 ----------------------------------------
101
 272448      119222     49901      222547    
102
 -----------------------------------------
103
TLD finalize... completed [ 03/9/23 12:00:35 ]
104

    
105
Saving DNSBL statistics... completed [ 03/9/23 12:00:36 ]
106
Reloading Unbound Resolver (DNSBL python).
107
Stopping Unbound Resolver.
108
Unbound stopped in 2 sec.
109
Additional mounts (DNSBL python):
110
  No changes required.
111
Starting Unbound Resolver... completed [ 03/9/23 12:00:38 ]
112
Resolver cache restored
113
DNSBL update [ 222547 | PASSED  ]... completed
114
------------------------------------------------------------------------
115

    
116
===[  GeoIP Process  ]============================================
117

    
118
[ pfB_Top_v4 ]			 exists.
119
[ pfB_Top_v6 ]			 exists.
120

    
121
===[  IPv4 Process  ]=================================================
122

    
123
[ Abuse_Feodo_C2_v4 ]		 Downloading update .. 200 OK. completed ..
124
  ------------------------------
125
  Original Master     Final     
126
  ------------------------------
127
  248      142        142         [ Pass ] 
128
  -----------------------------------------------------------------
129

    
130
[ Abuse_SSLBL_v4 ]		 Downloading update [ 03/9/23 12:00:40 ] .. 200 OK. completed ..
131

    
132
  Aggregation Stats:
133
  ------------------
134
  Original Final      
135
  ------------------
136
  44       43         
137
  ------------------
138
  ------------------------------
139
  Original Master     Final     
140
  ------------------------------
141
  44       31         31          [ Pass ] 
142
  -----------------------------------------------------------------
143

    
144
[ CINS_army_v4 ]		 Downloading update [ 03/9/23 12:00:41 ] .. 200 OK. completed ..
145

    
146
  Aggregation Stats:
147
  ------------------
148
  Original Final      
149
  ------------------
150
  15000    13891      
151
  ------------------
152
  ------------------------------
153
  Original Master     Final     
154
  ------------------------------
155
  15000    8878       8878        [ Pass ] 
156
  -----------------------------------------------------------------
157

    
158
[ ET_Block_v4 ]			 exists. [ 03/9/23 12:00:43 ]
159
[ ET_Comp_v4 ]			 exists.
160
[ ISC_Block_v4 ]		 Downloading update .. 200 OK. completed ..
161

    
162
  Aggregation Stats:
163
  ------------------
164
  Original Final      
165
  ------------------
166
  40       20         
167
  ------------------
168
  ------------------------------
169
  Original Master     Final     
170
  ------------------------------
171
  20       3          3           [ Pass ] 
172
  -----------------------------------------------------------------
173

    
174
[ Spamhaus_Drop_v4 ]		 exists. [ 03/9/23 12:00:45 ]
175
[ Spamhaus_eDrop_v4 ]		 exists.
176
[ Talos_BL_v4 ]			 exists.
177
[ Bogons4_v4 ]			 exists.
178

    
179
===[  IPv6 Process  ]=================================================
180

    
181
[ Bogons6_v6 ]			 exists.
182

    
183
===[  Aliastables / Rules  ]==========================================
184

    
185
No changes to Firewall rules, skipping Filter Reload
186

    
187
 Updating: pfB_PRI1_v4
188
206 addresses added.225 addresses deleted.
189

    
190
===[ FINAL Processing ]=====================================
191

    
192
   [ Original IP count   ]  [ 75020 ]
193

    
194
   [ Final IP Count  ]  [ 64479 ]
195

    
196

    
197
===[ Deny List IP Counts ]===========================
198

    
199
  224811 total
200
  139117 /var/db/pfblockerng/deny/Bogons6_v6.txt
201
   52137 /var/db/pfblockerng/deny/pfB_Top_v4.txt
202
   21215 /var/db/pfblockerng/deny/pfB_Top_v6.txt
203
    8878 /var/db/pfblockerng/deny/CINS_army_v4.txt
204
    1179 /var/db/pfblockerng/deny/ET_Block_v4.txt
205
    1012 /var/db/pfblockerng/deny/Bogons4_v4.txt
206
     621 /var/db/pfblockerng/deny/Talos_BL_v4.txt
207
     325 /var/db/pfblockerng/deny/ET_Comp_v4.txt
208
     149 /var/db/pfblockerng/deny/Spamhaus_eDrop_v4.txt
209
     142 /var/db/pfblockerng/deny/Abuse_Feodo_C2_v4.txt
210
      31 /var/db/pfblockerng/deny/Abuse_SSLBL_v4.txt
211
       3 /var/db/pfblockerng/deny/ISC_Block_v4.txt
212
       2 /var/db/pfblockerng/deny/Spamhaus_Drop_v4.txt
213

    
214
===[ DNSBL Domain/IP Counts ] ===================================
215

    
216
  272448 total
217
  176100 /var/db/pfblockerng/dnsbl/StevenBlack_ADs.txt
218
   43877 /var/db/pfblockerng/dnsbl/SFS_ToxicDW.txt
219
   21730 /var/db/pfblockerng/dnsbl/EasyList.txt
220
   15289 /var/db/pfblockerng/dnsbl/EasyPrivacy.txt
221
   14779 /var/db/pfblockerng/dnsbl/MalwareFilter.txt
222
     386 /var/db/pfblockerng/dnsbl/OpenPhish.txt
223
     287 /var/db/pfblockerng/dnsbl/WindowsSpyBlocker.txt
224

    
225
====================[ IPv4/6 Last Updated List Summary ]==============
226

    
227
Mar 3	15:00	pfB_Top_v4
228
Mar 3	15:00	pfB_Top_v6
229
Mar 5	19:01	Bogons4_v4
230
Mar 5	19:01	Bogons6_v6
231
Mar 7	23:30	ET_Block_v4
232
Mar 8	16:07	ET_Comp_v4
233
Mar 9	00:04	Talos_BL_v4
234
Mar 9	04:24	Spamhaus_Drop_v4
235
Mar 9	04:32	Spamhaus_eDrop_v4
236
Mar 9	11:18	CINS_army_v4
237
Mar 9	11:30	ISC_Block_v4
238
Mar 9	11:55	Abuse_SSLBL_v4
239
Mar 9	11:55	Abuse_Feodo_C2_v4
240

    
241
====================[ DNSBL Last Updated List Summary ]==============
242

    
243
Feb 12	20:00	WindowsSpyBlocker
244
Mar 8	00:00	StevenBlack_ADs
245
Mar 9	06:00	OpenPhish
246
Mar 9	06:30	MalwareFilter
247
Mar 9	11:00	SFS_ToxicDW
248
Mar 9	11:20	EasyPrivacy
249
Mar 9	11:20	EasyList
250
===============================================================
251

    
252
Database Sanity check [  PASSED  ]
253
------------------------
254
Masterfile/Deny folder uniq check
255
Deny folder/Masterfile uniq check
256

    
257
Sync check (Pass=No IPs reported)
258
----------
259

    
260
Alias table IP Counts
261
-----------------------------
262
  224811 total
263
  139117 /var/db/aliastables/pfB_Bogons_v6.txt
264
   52137 /var/db/aliastables/pfB_Top_v4.txt
265
   21215 /var/db/aliastables/pfB_Top_v6.txt
266
   11330 /var/db/aliastables/pfB_PRI1_v4.txt
267
    1012 /var/db/aliastables/pfB_Bogons_v4.txt
268

    
269
pfSense Table Stats
270
-------------------
271
table-entries hard limit  4000000
272
Table Usage Count         226244
273

    
274
 UPDATE PROCESS ENDED [ 03/9/23 12:00:46 ]
275
 CRON  PROCESS  START [ v3.2.0_3 ] [ 03/9/23 13:00:00 ]
276
[ Abuse_Feodo_C2_v4 ]
277
  Remote timestamp: Thu, 9 Mar 2023 18:55:03 GMT
278
  Local  timestamp: Thu, 9 Mar 2023 17:55:03 GMT	Update found
279
[ Abuse_SSLBL_v4 ]
280
  Remote timestamp: Thu, 9 Mar 2023 18:55:01 GMT
281
  Local  timestamp: Thu, 9 Mar 2023 17:55:01 GMT	Update found
282
[ CINS_army_v4 ] [ 03/9/23 13:00:01 ]
283
  Remote timestamp: Thu, 9 Mar 2023 17:18:18 GMT
284
  Local  timestamp: Thu, 9 Mar 2023 17:18:18 GMT	Update not required
285
[ ET_Block_v4 ]
286
  Remote timestamp: Wed, 8 Mar 2023 05:30:01 GMT
287
  Local  timestamp: Wed, 8 Mar 2023 05:30:01 GMT	Update not required
288
[ ET_Comp_v4 ] [ 03/9/23 13:00:08 ]
289
  Remote timestamp: Wed, 8 Mar 2023 22:07:08 GMT
290
  Local  timestamp: Wed, 8 Mar 2023 22:07:08 GMT	Update not required
291
[ ISC_Block_v4 ] [ 03/9/23 13:00:11 ]
292
  Remote timestamp: Thu, 9 Mar 2023 18:55:28 GMT
293
  Local  timestamp: Thu, 9 Mar 2023 17:30:29 GMT	Update found
294
[ Spamhaus_Drop_v4 ] [ 03/9/23 13:00:12 ]
295
  Remote timestamp: Thu, 9 Mar 2023 10:24:16 GMT
296
  Local  timestamp: Thu, 9 Mar 2023 10:24:16 GMT	Update not required
297
[ Spamhaus_eDrop_v4 ] [ 03/9/23 13:00:13 ]
298
  Remote timestamp: Thu, 9 Mar 2023 10:32:13 GMT
299
  Local  timestamp: Thu, 9 Mar 2023 10:32:13 GMT	Update not required
300
[ Talos_BL_v4 ] [ 03/9/23 13:00:14 ]
301
  Max daily download failure attempts exceeded. Clear widget 'failed downloads' to reset.
302

    
303
 UPDATE PROCESS START [ v3.2.0_3 ] [ 03/9/23 13:00:15 ]
304

    
305
===[  DNSBL Process  ]================================================
306

    
307
 Loading DNSBL Statistics... completed
308
 Loading DNSBL SafeSearch... disabled
309
 Loading DNSBL Whitelist... completed
310

    
311
[ EasyList ]			 exists.
312
[ EasyPrivacy ]			 exists.
313
[ StevenBlack_ADs ]		 exists.
314
[ MalwareFilter ]		 exists.
315
[ OpenPhish ]			 exists.
316
[ SFS_ToxicDW ]			 exists.
317
[ WindowsSpyBlocker ]		 exists.
318

    
319
===[  GeoIP Process  ]============================================
320

    
321
[ pfB_Top_v4 ]			 exists. [ 03/9/23 13:00:16 ]
322
[ pfB_Top_v6 ]			 exists.
323

    
324
===[  IPv4 Process  ]=================================================
325

    
326
[ Abuse_Feodo_C2_v4 ]		 Downloading update .. 200 OK. completed ..
327
  ------------------------------
328
  Original Master     Final     
329
  ------------------------------
330
  243      142        142         [ Pass ] 
331
  -----------------------------------------------------------------
332

    
333
[ Abuse_SSLBL_v4 ]		 Downloading update [ 03/9/23 13:00:17 ] .. 200 OK. completed ..
334

    
335
  Aggregation Stats:
336
  ------------------
337
  Original Final      
338
  ------------------
339
  44       43         
340
  ------------------
341
  ------------------------------
342
  Original Master     Final     
343
  ------------------------------
344
  44       31         31          [ Pass ] 
345
  -----------------------------------------------------------------
346

    
347
[ CINS_army_v4 ]		 exists. [ 03/9/23 13:00:18 ]
348
[ ET_Block_v4 ]			 exists.
349
[ ET_Comp_v4 ]			 exists.
350
[ ISC_Block_v4 ]		 Downloading update .. 200 OK. completed ..
351

    
352
  Aggregation Stats:
353
  ------------------
354
  Original Final      
355
  ------------------
356
  40       20         
357
  ------------------
358
  ------------------------------
359
  Original Master     Final     
360
  ------------------------------
361
  20       3          3           [ Pass ] 
362
  -----------------------------------------------------------------
363

    
364
[ Spamhaus_Drop_v4 ]		 exists.
365
[ Spamhaus_eDrop_v4 ]		 exists.
366
[ Talos_BL_v4 ]			 exists.
367
[ Bogons4_v4 ]			 exists.
368

    
369
===[  IPv6 Process  ]=================================================
370

    
371
[ Bogons6_v6 ]			 exists.
372
===[  Aliastables / Rules  ]================================
373

    
374
Firewall rule changes found, applying Filter Reload
375

    
376

    
377
** Restarting firewall filter daemon **
378

    
379
===[ FINAL Processing ]=====================================
380

    
381
   [ Original IP count   ]  [ 75015 ]
382

    
383
   [ Final IP Count  ]  [ 64479 ]
384

    
385

    
386
===[ Deny List IP Counts ]===========================
387

    
388
  224811 total
389
  139117 /var/db/pfblockerng/deny/Bogons6_v6.txt
390
   52137 /var/db/pfblockerng/deny/pfB_Top_v4.txt
391
   21215 /var/db/pfblockerng/deny/pfB_Top_v6.txt
392
    8878 /var/db/pfblockerng/deny/CINS_army_v4.txt
393
    1179 /var/db/pfblockerng/deny/ET_Block_v4.txt
394
    1012 /var/db/pfblockerng/deny/Bogons4_v4.txt
395
     621 /var/db/pfblockerng/deny/Talos_BL_v4.txt
396
     325 /var/db/pfblockerng/deny/ET_Comp_v4.txt
397
     149 /var/db/pfblockerng/deny/Spamhaus_eDrop_v4.txt
398
     142 /var/db/pfblockerng/deny/Abuse_Feodo_C2_v4.txt
399
      31 /var/db/pfblockerng/deny/Abuse_SSLBL_v4.txt
400
       3 /var/db/pfblockerng/deny/ISC_Block_v4.txt
401
       2 /var/db/pfblockerng/deny/Spamhaus_Drop_v4.txt
402

    
403
===[ DNSBL Domain/IP Counts ] ===================================
404

    
405
  272448 total
406
  176100 /var/db/pfblockerng/dnsbl/StevenBlack_ADs.txt
407
   43877 /var/db/pfblockerng/dnsbl/SFS_ToxicDW.txt
408
   21730 /var/db/pfblockerng/dnsbl/EasyList.txt
409
   15289 /var/db/pfblockerng/dnsbl/EasyPrivacy.txt
410
   14779 /var/db/pfblockerng/dnsbl/MalwareFilter.txt
411
     386 /var/db/pfblockerng/dnsbl/OpenPhish.txt
412
     287 /var/db/pfblockerng/dnsbl/WindowsSpyBlocker.txt
413

    
414
====================[ IPv4/6 Last Updated List Summary ]==============
415

    
416
Mar 3	15:00	pfB_Top_v4
417
Mar 3	15:00	pfB_Top_v6
418
Mar 5	19:01	Bogons4_v4
419
Mar 5	19:01	Bogons6_v6
420
Mar 7	23:30	ET_Block_v4
421
Mar 8	16:07	ET_Comp_v4
422
Mar 9	00:04	Talos_BL_v4
423
Mar 9	04:24	Spamhaus_Drop_v4
424
Mar 9	04:32	Spamhaus_eDrop_v4
425
Mar 9	11:18	CINS_army_v4
426
Mar 9	12:30	ISC_Block_v4
427
Mar 9	12:55	Abuse_SSLBL_v4
428
Mar 9	12:55	Abuse_Feodo_C2_v4
429

    
430
====================[ DNSBL Last Updated List Summary ]==============
431

    
432
Feb 12	20:00	WindowsSpyBlocker
433
Mar 8	00:00	StevenBlack_ADs
434
Mar 9	06:00	OpenPhish
435
Mar 9	06:30	MalwareFilter
436
Mar 9	11:00	SFS_ToxicDW
437
Mar 9	11:20	EasyPrivacy
438
Mar 9	11:20	EasyList
439
===============================================================
440

    
441
Database Sanity check [  PASSED  ]
442
------------------------
443
Masterfile/Deny folder uniq check
444
Deny folder/Masterfile uniq check
445

    
446
Sync check (Pass=No IPs reported)
447
----------
448

    
449
Alias table IP Counts
450
-----------------------------
451
  224811 total
452
  139117 /var/db/aliastables/pfB_Bogons_v6.txt
453
   52137 /var/db/aliastables/pfB_Top_v4.txt
454
   21215 /var/db/aliastables/pfB_Top_v6.txt
455
   11330 /var/db/aliastables/pfB_PRI1_v4.txt
456
    1012 /var/db/aliastables/pfB_Bogons_v4.txt
457

    
458
pfSense Table Stats
459
-------------------
460
table-entries hard limit  4000000
461
Table Usage Count         1419
462

    
463
 UPDATE PROCESS ENDED [ 03/9/23 13:00:20 ]
(2-2/2)