<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: dht_pkt_alert Possible malicious infection in CDH6 in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/dht-pkt-alert-Possible-malicious-infection-in-CDH6/m-p/388349#M246642</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/110791"&gt;@robert199re&lt;/a&gt;&amp;nbsp;for the information, the&amp;nbsp; system is isolated, I would do some additional investigations but not I can asume that this traffic is not usual for CDH6.&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;</description>
    <pubDate>Mon, 27 May 2024 07:28:19 GMT</pubDate>
    <dc:creator>Juanes</dc:creator>
    <dc:date>2024-05-27T07:28:19Z</dc:date>
    <item>
      <title>dht_pkt_alert Possible malicious infection in CDH6</title>
      <link>https://community.cloudera.com/t5/Support-Questions/dht-pkt-alert-Possible-malicious-infection-in-CDH6/m-p/388194#M246569</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;I have an old CDH6 and realized the following suspicious traces in cloudera.flood.log in&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class="ui-provider bbp bbq bbh bbr bbs bbt bbu bbv bbw bbx bby bbz bca bcb bcc bcd bce bcf bcg bch bci bcj bck bcl bcm bcn bco bcp bcq bcr bcs bct bcu bcv bcw"&gt;/var/log/cloudera-scm-server&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Juanes_0-1716361541025.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/40748i2D9A4140376F31EC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Juanes_0-1716361541025.png" alt="Juanes_0-1716361541025.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;dht_pkt_alert &lt;/SPAN&gt;&lt;SPAN&gt;==&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN&gt;82.43&lt;/SPAN&gt;&lt;SPAN&gt;.248.101:&lt;/SPAN&gt;&lt;SPAN&gt;6881&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;dht_pkt_alert &lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;==&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN&gt;82.43&lt;/SPAN&gt;&lt;SPAN&gt;.248.101:&lt;/SPAN&gt;&lt;SPAN&gt;6881&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;and the same for another almost 100 different IPs outside the network by using the p2p libraries (and not sure that they are Cloudera Repository Ps)&lt;/P&gt;&lt;P&gt;Did you see anything similar? this activity is quite suspicious.&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider bbp bbq bbh bbr bbs bbt bbu bbv bbw bbx bby bbz bca bcb bcc bcd bce bcf bcg bch bci bcj bck bcl bcm bcn bco bcp bcq bcr bcs bct bcu bcv bcw"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 07:09:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/dht-pkt-alert-Possible-malicious-infection-in-CDH6/m-p/388194#M246569</guid>
      <dc:creator>Juanes</dc:creator>
      <dc:date>2024-05-22T07:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: dht_pkt_alert Possible malicious infection in CDH6</title>
      <link>https://community.cloudera.com/t5/Support-Questions/dht-pkt-alert-Possible-malicious-infection-in-CDH6/m-p/388308#M246623</link>
      <description>&lt;P&gt;The dht_pkt_alert messages you’re seeing in the cloudera.flood.log are indicative of Distributed Hash Table (DHT) packet alerts, which are associated with peer-to-peer (P2P) network activity. This type of activity is unusual for a Cloudera CDH6 environment and could potentially point to a security concern, such as unauthorized software or a compromised system.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 09:53:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/dht-pkt-alert-Possible-malicious-infection-in-CDH6/m-p/388308#M246623</guid>
      <dc:creator>robert199re</dc:creator>
      <dc:date>2024-05-24T09:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: dht_pkt_alert Possible malicious infection in CDH6</title>
      <link>https://community.cloudera.com/t5/Support-Questions/dht-pkt-alert-Possible-malicious-infection-in-CDH6/m-p/388349#M246642</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/110791"&gt;@robert199re&lt;/a&gt;&amp;nbsp;for the information, the&amp;nbsp; system is isolated, I would do some additional investigations but not I can asume that this traffic is not usual for CDH6.&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 07:28:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/dht-pkt-alert-Possible-malicious-infection-in-CDH6/m-p/388349#M246642</guid>
      <dc:creator>Juanes</dc:creator>
      <dc:date>2024-05-27T07:28:19Z</dc:date>
    </item>
  </channel>
</rss>

