RouterOS making unaccounted outbound winbox connections

360 Netlab are tweeting: “So the old Hajime botnet is coming back with a new exploit which was published only about 13 days ago ( https://www.exploit-db.com/exploits/44284/ ), it also looks for some old exploits like tr-064 but nothing exciting there.” — https://twitter.com/360Netlab/status/977932206835462146

They spotted increased scanning earlier in the day — https://twitter.com/360Netlab/status/977732944273068032