Good morning.
I today configured external firewall and detected some blocked attempts. After i started investigation i found exact process which create traffic to weird public ip and port 80. Such connection attempts try to establish over all physical interfaces on computer.
This is netstat statistics :
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 172.27.0.2:53904 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 10.111.111.32:54696 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 10.111.111.32:54696 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 10.111.111.130:48922 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 10.111.111.32:54696 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 10.111.111.130:48922 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
tcp 0 1 192.168.43.9:58998 116.203.91.91:80 SYN_SENT 795/NetworkManager
795 ? Ssl 14:40 /usr/bin/NetworkManager --no-daemon
Do somebody know what it can be ? I not see anywhere in configuration of network manager such ip address. Something hardcoded ?