Am I attacked?

Hi all!

I have realized that my DNS configuration is changed to this ones:

164.124.101.2
168.126.63.2

Theese IPs are from South Korea.

Does anyone know if this is normal? My FreePBX is well protected, or that’s what I think.

  • I have one port redirected (not default one) to the SSH of the freePBX, and have no more ports opened.
  • Fail to ban is working as well.
  • Freepbx passwords are difficult enough.
  • I always use ssh port forwarding to access the web interface, also for phones configuration

Am I paranoid?

Regards