Snort mailing list archives
Received email alert from pfSense firewall + Snort Intrusion Prevention System (IPS) suggesting that my Linux Server in Germany was hacked by APT hackers and it was used to port scan my home pfsense firewall in Singapore
From: Turritopsis Dohrnii Teo En Ming via Snort-devel <snort-devel () lists snort org>
Date: Wed, 30 Sep 2026 04:22:16 +0000
Subject: Received email alert from pfSense firewall + Snort Intrusion Prevention System (IPS) suggesting that my Linux
Server in Germany was hacked by APT hackers and it was used to port scan my home pfsense firewall in Singapore
Good day from Singapore,
At approximately 6:48 PM (Singapore time) on 29 September 2026 Tuesday, I received a security alert generated by the
Snort Intrusion Prevention System (IPS) running on my home pfSense firewall in Singapore.
The alert indicates that traffic originating from the public IP address 217.a.b.74, which is assigned to my Contabo VPS
hosting my Virtualmin master server in Germany, was detected by Snort as a UDP Filtered Decoy Portscan
against my home Internet connection in Singapore.
I am concerned about this activity because I am not aware of any legitimate reason why my Linux VPS in Germany should
be generating traffic that Snort identifies as a port scan against my home Internet connection in Singapore.
I suspect Advanced Persistent Threats (APT) hackers had hacked into and taken control over my Linux VPS in Germany and
used it to perform port scan against my home pfSense firewall in Singapore.
The Snort alert is reproduced below:
pfSense/Snort Security Alert
Alert Type:
PORT SCAN
Time:
2026-09-29 18:48:05
Original Syslog Message:
2026-09-29 18:48:03 Auth.Alert 192.168.88.1 Sep 29 18:48:03 snort[52837]: [122:22:1] (portscan) UDP Filtered Decoy
Portscan [Classification: Attempted Information Leak] [Priority: 2] {PROTO:255} 217.a.b.74 -> 49.x.y.89
Source IP: 217.a.b.74 — my Contabo VPS / Virtualmin server in Germany
Destination IP: 49.x.y.89 — my home pfSense firewall in Singapore
Subsequent hacking incident forensic investigation carried out by ChatGPT artificial intelligence (AI) more or less
confirmed that my Snort IPS had likely produced a false positive / false alarm.
The forensic investigation started around 11.30 PM late at night on 29 Sep 2026 Tuesday and paused around 2.00 AM in
the morning on 30 Sep 2026 Wednesday (Singapore Time).
As there is still an unexplained phenomenon, forensic investigation will continue once I have the free time.
Regards,
Mr. Turritopsis Dohrnii Teo En Ming
Republic of Singapore
30 Sep 2026 Wednesday 12.08 pm Singapore Time
_______________________________________________
Snort-devel mailing list
Snort-devel () lists snort org
https://lists.snort.org/mailman/listinfo/snort-devel
Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- Received email alert from pfSense firewall + Snort Intrusion Prevention System (IPS) suggesting that my Linux Server in Germany was hacked by APT hackers and it was used to port scan my home pfsense firewall in Singapore Turritopsis Dohrnii Teo En Ming via Snort-devel (Oct 02)
