My IPS/IPD gateway has blocked outgoing connections to port 22. I have traced them down and confirm they were originated from from my qbittorrent container from image pulled from latest. It has been ongoing for awhile with previous latest images as well. The destination hosts are all bearing ....bc.googleusercontent.com domains.
My questions are:
- Any chance that they legitimate? Like some random bittorrent clients running on port 22?
- Is my container compromised?
Thanks in advance.