I have the following issue with my firewall. I am looking at the log and every second or so (with the processor being used at 100%) I see a message that an outbound ICMP request was blocked because of my policy rules. Well Thank God for that!
But my problem is that I am not able to identify which process is attempting to send out that ping! I am almost sure that it is malware of some kind because the IP addresses being pinged are different each time.
Right now it is trying an ICMP every 5 seconds or so.
e.g. for the past 5 attempts the following IP addresses are being pinged (form the HTML export feature of logging):
Date/Time :2007-10-28 08:28:32
Severity :Medium
Reporter :Network Monitor
Description:Outbound Policy Violation (Access Denied, ICMP = PORT UNREACHABLE)
Protocol:ICMP Outgoing
Source: 192.168.1.4
Destination: 77.221.73.90
Message: PORT UNREACHABLE
Reason: Network Control Rule ID = 16
Date/Time :2007-10-28 08:28:21
Severity :Medium
Reporter :Network Monitor
Description:Outbound Policy Violation (Access Denied, ICMP = PORT UNREACHABLE)
Protocol:ICMP Outgoing
Source: 192.168.1.4
Destination: 118.136.201.67
Message: PORT UNREACHABLE
Reason: Network Control Rule ID = 16
Date/Time :2007-10-28 08:26:25
Severity :Medium
Reporter :Network Monitor
Description:Outbound Policy Violation (Access Denied, ICMP = PORT UNREACHABLE)
Protocol:ICMP Outgoing
Source: 192.168.1.4
Destination: 89.32.55.228
Message: PORT UNREACHABLE
Reason: Network Control Rule ID = 16
Date/Time :2007-10-28 08:26:05
Severity :Medium
Reporter :Network Monitor
Description:Outbound Policy Violation (Access Denied, ICMP = PORT UNREACHABLE)
Protocol:ICMP Outgoing
Source: 192.168.1.4
Destination: 59.114.130.242
Message: PORT UNREACHABLE
Reason: Network Control Rule ID = 16
Date/Time :2007-10-28 08:25:34
Severity :Medium
Reporter :Network Monitor
Description:Outbound Policy Violation (Access Denied, ICMP = PORT UNREACHABLE)
Protocol:ICMP Outgoing
Source: 192.168.1.4
Destination: 117.25.28.31
Message: PORT UNREACHABLE
Reason: Network Control Rule ID = 16
Date/Time :2007-10-28 08:23:34
Severity :Medium
Reporter :Network Monitor
Description:Outbound Policy Violation (Access Denied, ICMP = PORT UNREACHABLE)
Protocol:ICMP Outgoing
Source: 192.168.1.4
Destination: 218.65.129.46
Message: PORT UNREACHABLE
Reason: Network Control Rule ID = 16
Date/Time :2007-10-28 08:21:23
Severity :Medium
Reporter :Network Monitor
Description:Outbound Policy Violation (Access Denied, ICMP = PORT UNREACHABLE)
Protocol:ICMP Outgoing
Source: 192.168.1.4
Destination: 84.68.216.34
Message: PORT UNREACHABLE
Reason: Network Control Rule ID = 16