Hi,
Looking at network traffic on the server I can see that there are periodic connections (every 10 seconds or so) made from the server to 188.166.4.132 on port 8001
https://ipinfo.io/188.166.132.40
My nextcloud installation is in a container by itself, no other services are installed there.
tcpdump -vv -i any -c10 -nn -A port 8001
reveals
05:12:10.504584 IP (tos 0x0, ttl 64, id 35143, offset 0, flags [DF], proto TCP (6), length 52)
10.32.10.30.45956 > 188.166.4.132.8001: Flags [.], cksum 0xd58e (incorrect -> 0x626e), seq 1811974046, ack 2256938967, win 242, options [nop,nop,TS val 2210015066 ecr 1593229095], length 0
E..4.G@.@...
........Al.....'............
..'Z^..'
05:12:10.535594 IP (tos 0x0, ttl 50, id 59453, offset 0, flags [DF], proto TCP (6), length 52)
188.166.4.132.8001 > 10.32.10.30.45956: Flags [.], cksum 0x6253 (correct), seq 1, ack 1, win 503, options [nop,nop,TS val 1593244199 ecr 2209999727], length 0
E..4.=@.2.......
..A....'.l.......bS.....
^..'...o
05:12:11.165590 IP (tos 0x0, ttl 50, id 59454, offset 0, flags [DF], proto TCP (6), length 52)
188.166.4.132.8001 > 10.32.10.30.45956: Flags [.], cksum 0x5fde (correct), seq 0, ack 1, win 503, options [nop,nop,TS val 1593244829 ecr 2209999727], length 0
E..4.>@.2.......
..A....'.l......._......
^......o
05:12:11.165608 IP (tos 0x0, ttl 64, id 35144, offset 0, flags [DF], proto TCP (6), length 52)
10.32.10.30.45956 > 188.166.4.132.8001: Flags [.], cksum 0xd58e (incorrect -> 0x24d8), seq 1, ack 1, win 242, options [nop,nop,TS val 2210015727 ecr 1593244199], length 0
E..4.H@.@...
........Al.....'............
..).^..'
Any ideas what this could be?
Thanks.