|
[LOGS] Summary of large-scale portscanning detects: msg#00037security.intrusions
The following extracts show the beginning and ending of scan activity was detected on my network. The number following each set is the total number of probes for that source. Timestamps are GMT-0500. May 12 13:28:40 61.134.11.253:4178 -> xxx.yyy.1.1:8080 SYN ******S* May 12 13:28:39 61.134.11.253:4182 -> xxx.yyy.1.1:3128 SYN ******S* May 12 13:28:39 61.134.11.253:4183 -> xxx.yyy.1.1:8000 SYN ******S* May 12 13:28:39 61.134.11.253:4202 -> xxx.yyy.1.3:1080 SYN ******S* May 12 13:28:42 61.134.11.253:4206 -> xxx.yyy.1.3:8000 SYN ******S* May 12 13:28:42 61.134.11.253:4194 -> xxx.yyy.1.3:8080 SYN ******S* May 12 13:28:42 61.134.11.253:4226 -> xxx.yyy.1.5:8000 SYN ******S* May 12 13:28:42 61.134.11.253:4223 -> xxx.yyy.1.5:3128 SYN ******S* [...] May 12 14:39:43 61.134.11.253:2649 -> xxx.yyy.zzz.254:3128 SYN ******S* May 12 14:39:43 61.134.11.253:2648 -> xxx.yyy.zzz.254:1080 SYN ******S* May 12 14:39:43 61.134.11.253:2646 -> xxx.yyy.zzz.254:8080 SYN ******S* May 12 14:39:43 61.134.11.253:2634 -> xxx.yyy.zzz.251:3128 SYN ******S* May 12 14:39:43 61.134.11.253:2633 -> xxx.yyy.zzz.251:1080 SYN ******S* May 12 14:39:43 61.134.11.253:2631 -> xxx.yyy.zzz.251:8080 SYN ******S* May 12 14:39:43 61.134.11.253:2640 -> xxx.yyy.zzz.252:8000 SYN ******S* May 12 14:39:43 61.134.11.253:2639 -> xxx.yyy.zzz.252:3128 SYN ******S* May 12 14:39:43 61.134.11.253:2636 -> xxx.yyy.zzz.252:8080 SYN ******S* 305461 May 12 01:45:04 80.142.42.92:1377 -> xxx.yyy.1.0:1433 SYN ******S* May 12 01:45:04 80.142.42.92:1379 -> xxx.yyy.1.1:1433 SYN ******S* May 12 01:45:04 80.142.42.92:1381 -> xxx.yyy.1.2:1433 SYN ******S* May 12 01:45:04 80.142.42.92:1383 -> xxx.yyy.1.3:1433 SYN ******S* May 12 01:45:05 80.142.42.92:1385 -> xxx.yyy.1.4:1433 SYN ******S* May 12 01:45:05 80.142.42.92:1387 -> xxx.yyy.1.5:1433 SYN ******S* May 12 01:45:05 80.142.42.92:1389 -> xxx.yyy.1.6:1433 SYN ******S* May 12 01:45:05 80.142.42.92:1391 -> xxx.yyy.1.7:1433 SYN ******S* [...] May 12 02:50:56 80.142.42.92:2185 -> xxx.yyy.255.247:1433 SYN ******S* May 12 02:50:56 80.142.42.92:2183 -> xxx.yyy.255.246:1433 SYN ******S* May 12 02:50:56 80.142.42.92:2189 -> xxx.yyy.255.249:1433 SYN ******S* May 12 02:50:56 80.142.42.92:2187 -> xxx.yyy.255.248:1433 SYN ******S* May 12 02:50:56 80.142.42.92:2191 -> xxx.yyy.255.250:1433 SYN ******S* May 12 02:50:56 80.142.42.92:2195 -> xxx.yyy.255.252:1433 SYN ******S* May 12 02:50:56 80.142.42.92:2193 -> xxx.yyy.255.251:1433 SYN ******S* May 12 02:50:56 80.142.42.92:2197 -> xxx.yyy.255.253:1433 SYN ******S* 78369 May 12 18:49:07 194.128.167.15:1879 -> xxx.yyy.1.2:1433 SYN ******S* May 12 18:49:07 194.128.167.15:1880 -> xxx.yyy.1.3:1433 SYN ******S* May 12 18:49:07 194.128.167.15:1881 -> xxx.yyy.1.4:1433 SYN ******S* May 12 18:49:07 194.128.167.15:1882 -> xxx.yyy.1.5:1433 SYN ******S* May 12 18:49:07 194.128.167.15:1883 -> xxx.yyy.1.6:1433 SYN ******S* May 12 18:49:07 194.128.167.15:1884 -> xxx.yyy.1.7:1433 SYN ******S* May 12 18:49:07 194.128.167.15:1885 -> xxx.yyy.1.8:1433 SYN ******S* May 12 18:49:07 194.128.167.15:1886 -> xxx.yyy.1.9:1433 SYN ******S* [...] May 12 19:00:04 194.128.167.15:4738 -> xxx.yyy.255.242:1433 SYN ******S* May 12 19:00:04 194.128.167.15:4745 -> xxx.yyy.255.249:1433 SYN ******S* May 12 19:00:04 194.128.167.15:4739 -> xxx.yyy.255.243:1433 SYN ******S* May 12 19:00:04 194.128.167.15:4742 -> xxx.yyy.255.246:1433 SYN ******S* May 12 19:00:04 194.128.167.15:4749 -> xxx.yyy.255.253:1433 SYN ******S* May 12 19:00:04 194.128.167.15:4750 -> xxx.yyy.255.254:1433 SYN ******S* May 12 19:00:04 194.128.167.15:4747 -> xxx.yyy.255.251:1433 SYN ******S* May 12 19:00:04 194.128.167.15:4748 -> xxx.yyy.255.252:1433 SYN ******S* 73797 May 12 05:47:18 204.57.62.99:4217 -> xxx.yyy.1.1:5554 SYN ******S* May 12 05:47:18 204.57.62.99:4219 -> xxx.yyy.1.2:5554 SYN ******S* May 12 05:47:20 204.57.62.99:4220 -> xxx.yyy.1.3:5554 SYN ******S* May 12 05:47:20 204.57.62.99:4221 -> xxx.yyy.1.4:5554 SYN ******S* May 12 05:47:20 204.57.62.99:4223 -> xxx.yyy.1.5:5554 SYN ******S* May 12 05:47:20 204.57.62.99:4224 -> xxx.yyy.1.6:5554 SYN ******S* May 12 05:47:20 204.57.62.99:4225 -> xxx.yyy.1.7:5554 SYN ******S* May 12 05:47:20 204.57.62.99:4226 -> xxx.yyy.1.8:5554 SYN ******S* [...] May 12 05:58:16 204.57.62.99:3862 -> xxx.yyy.255.242:5554 SYN ******S* May 12 05:58:16 204.57.62.99:3866 -> xxx.yyy.255.245:5554 SYN ******S* May 12 05:58:16 204.57.62.99:3867 -> xxx.yyy.255.246:5554 SYN ******S* May 12 05:58:16 204.57.62.99:3863 -> xxx.yyy.255.243:5554 SYN ******S* May 12 05:58:16 204.57.62.99:3871 -> xxx.yyy.255.249:5554 SYN ******S* May 12 05:58:16 204.57.62.99:3876 -> xxx.yyy.255.252:5554 SYN ******S* May 12 05:58:16 204.57.62.99:3877 -> xxx.yyy.255.253:5554 SYN ******S* May 12 05:58:16 204.57.62.99:3878 -> xxx.yyy.255.254:5554 SYN ******S* 73365 May 12 14:44:39 213.210.12.232:4179 -> xxx.yyy.1.1:445 SYN ******S* May 12 14:44:39 213.210.12.232:4182 -> xxx.yyy.1.2:445 SYN ******S* May 12 14:44:39 213.210.12.232:4183 -> xxx.yyy.1.3:445 SYN ******S* May 12 14:44:39 213.210.12.232:4184 -> xxx.yyy.1.4:445 SYN ******S* May 12 14:44:39 213.210.12.232:4187 -> xxx.yyy.1.5:445 SYN ******S* May 12 14:44:39 213.210.12.232:4188 -> xxx.yyy.1.6:445 SYN ******S* May 12 14:44:39 213.210.12.232:4189 -> xxx.yyy.1.7:445 SYN ******S* May 12 14:44:39 213.210.12.232:4192 -> xxx.yyy.1.8:445 SYN ******S* [...] May 12 14:56:01 213.210.12.232:3508 -> xxx.yyy.254.183:445 SYN ******S* May 12 14:56:01 213.210.12.232:3500 -> xxx.yyy.254.178:445 SYN ******S* May 12 14:56:01 213.210.12.232:3506 -> xxx.yyy.254.181:445 SYN ******S* May 12 14:56:01 213.210.12.232:3511 -> xxx.yyy.254.184:445 SYN ******S* May 12 14:56:01 213.210.12.232:3502 -> xxx.yyy.254.179:445 SYN ******S* May 12 14:56:01 213.210.12.232:3507 -> xxx.yyy.254.182:445 SYN ******S* May 12 14:56:01 213.210.12.232:3512 -> xxx.yyy.254.185:445 SYN ******S* May 12 14:56:02 213.210.12.232:3577 -> xxx.yyy.254.223:445 SYN ******S* May 12 14:56:02 213.210.12.232:3581 -> xxx.yyy.254.225:445 SYN ******S* 73333 May 12 23:23:06 199.72.57.235:4778 -> xxx.yyy.1.1:445 SYN ******S* May 12 23:23:06 199.72.57.235:4779 -> xxx.yyy.1.2:445 SYN ******S* May 12 23:23:06 199.72.57.235:4780 -> xxx.yyy.1.3:445 SYN ******S* May 12 23:23:06 199.72.57.235:4781 -> xxx.yyy.1.4:445 SYN ******S* May 12 23:23:03 199.72.57.235:4782 -> xxx.yyy.1.5:445 SYN ******S* May 12 23:23:03 199.72.57.235:4785 -> xxx.yyy.1.6:445 SYN ******S* May 12 23:23:06 199.72.57.235:4786 -> xxx.yyy.1.7:445 SYN ******S* May 12 23:23:06 199.72.57.235:4788 -> xxx.yyy.1.8:445 SYN ******S* [...] May 12 23:34:44 199.72.57.235:4584 -> xxx.yyy.255.240:445 SYN ******S* May 12 23:34:44 199.72.57.235:4622 -> xxx.yyy.255.253:445 SYN ******S* May 12 23:34:44 199.72.57.235:4606 -> xxx.yyy.255.248:445 SYN ******S* May 12 23:34:44 199.72.57.235:4608 -> xxx.yyy.255.249:445 SYN ******S* May 12 23:34:44 199.72.57.235:4610 -> xxx.yyy.255.250:445 SYN ******S* May 12 23:34:44 199.72.57.235:4618 -> xxx.yyy.255.252:445 SYN ******S* May 12 23:34:44 199.72.57.235:4615 -> xxx.yyy.255.251:445 SYN ******S* May 12 23:34:44 199.72.57.235:4625 -> xxx.yyy.255.254:445 SYN ******S* 71619 May 12 11:03:55 213.176.151.205:4587 -> xxx.yyy.1.1:443 SYN ******S* May 12 11:03:55 213.176.151.205:4589 -> xxx.yyy.1.2:443 SYN ******S* May 12 11:03:56 213.176.151.205:4594 -> xxx.yyy.1.3:443 SYN ******S* May 12 11:03:56 213.176.151.205:4596 -> xxx.yyy.1.4:443 SYN ******S* May 12 11:03:56 213.176.151.205:4599 -> xxx.yyy.1.5:443 SYN ******S* May 12 11:03:56 213.176.151.205:4602 -> xxx.yyy.1.6:443 SYN ******S* May 12 11:03:56 213.176.151.205:4604 -> xxx.yyy.1.7:443 SYN ******S* May 12 11:03:56 213.176.151.205:4607 -> xxx.yyy.1.8:443 SYN ******S* [...] May 12 11:14:49 213.176.151.205:3384 -> xxx.yyy.255.240:443 SYN ******S* May 12 11:14:49 213.176.151.205:3386 -> xxx.yyy.255.241:443 SYN ******S* May 12 11:14:49 213.176.151.205:3398 -> xxx.yyy.255.247:443 SYN ******S* May 12 11:14:49 213.176.151.205:3394 -> xxx.yyy.255.245:443 SYN ******S* May 12 11:14:49 213.176.151.205:3388 -> xxx.yyy.255.242:443 SYN ******S* May 12 11:14:49 213.176.151.205:3400 -> xxx.yyy.255.248:443 SYN ******S* May 12 11:14:49 213.176.151.205:3390 -> xxx.yyy.255.243:443 SYN ******S* May 12 11:14:49 213.176.151.205:3396 -> xxx.yyy.255.246:443 SYN ******S* 70524 May 12 00:48:27 66.223.110.246:44350 -> xxx.yyy.1.1:5554 SYN ******S* May 12 00:48:27 66.223.110.246:44353 -> xxx.yyy.1.2:5554 SYN ******S* May 12 00:48:25 66.223.110.246:44356 -> xxx.yyy.1.3:5554 SYN ******S* May 12 00:48:25 66.223.110.246:44359 -> xxx.yyy.1.4:5554 SYN ******S* May 12 00:48:28 66.223.110.246:44362 -> xxx.yyy.1.5:5554 SYN ******S* May 12 00:48:28 66.223.110.246:44365 -> xxx.yyy.1.6:5554 SYN ******S* May 12 00:48:28 66.223.110.246:44368 -> xxx.yyy.1.7:5554 SYN ******S* May 12 00:48:28 66.223.110.246:44371 -> xxx.yyy.1.8:5554 SYN ******S* [...] May 12 01:01:27 66.223.110.246:48216 -> xxx.yyy.255.246:5554 SYN ******S* May 12 01:01:27 66.223.110.246:48219 -> xxx.yyy.255.247:5554 SYN ******S* May 12 01:01:27 66.223.110.246:48210 -> xxx.yyy.255.244:5554 SYN ******S* May 12 01:01:27 66.223.110.246:48231 -> xxx.yyy.255.251:5554 SYN ******S* May 12 01:01:27 66.223.110.246:48237 -> xxx.yyy.255.253:5554 SYN ******S* May 12 01:01:27 66.223.110.246:48228 -> xxx.yyy.255.250:5554 SYN ******S* May 12 01:01:27 66.223.110.246:48240 -> xxx.yyy.255.254:5554 SYN ******S* May 12 01:01:27 66.223.110.246:48225 -> xxx.yyy.255.249:5554 SYN ******S* May 12 01:01:27 66.223.110.246:48234 -> xxx.yyy.255.252:5554 SYN ******S* 68690 May 12 18:16:13 68.90.58.202:1079 -> xxx.yyy.1.1:5554 SYN ******S* May 12 18:16:13 68.90.58.202:1080 -> xxx.yyy.1.2:5554 SYN ******S* May 12 18:16:14 68.90.58.202:1081 -> xxx.yyy.1.3:5554 SYN ******S* May 12 18:16:14 68.90.58.202:1082 -> xxx.yyy.1.4:5554 SYN ******S* May 12 18:16:14 68.90.58.202:1083 -> xxx.yyy.1.5:5554 SYN ******S* May 12 18:16:14 68.90.58.202:1084 -> xxx.yyy.1.6:5554 SYN ******S* May 12 18:16:14 68.90.58.202:1085 -> xxx.yyy.1.7:5554 SYN ******S* May 12 18:16:11 68.90.58.202:1086 -> xxx.yyy.1.8:5554 SYN ******S* [...] May 12 18:28:05 68.90.58.202:2662 -> xxx.yyy.255.229:5554 SYN ******S* May 12 18:28:05 68.90.58.202:2671 -> xxx.yyy.255.238:5554 SYN ******S* May 12 18:28:05 68.90.58.202:2675 -> xxx.yyy.255.242:5554 SYN ******S* May 12 18:28:05 68.90.58.202:2672 -> xxx.yyy.255.239:5554 SYN ******S* May 12 18:28:05 68.90.58.202:2676 -> xxx.yyy.255.243:5554 SYN ******S* May 12 18:28:05 68.90.58.202:2673 -> xxx.yyy.255.240:5554 SYN ******S* May 12 18:28:05 68.90.58.202:2670 -> xxx.yyy.255.237:5554 SYN ******S* May 12 18:28:05 68.90.58.202:2674 -> xxx.yyy.255.241:5554 SYN ******S* 68667 May 12 13:27:00 209.196.128.253:4737 -> xxx.yyy.1.1:20168 SYN ******S* May 12 13:27:00 209.196.128.253:4738 -> xxx.yyy.1.2:20168 SYN ******S* May 12 13:26:59 209.196.128.253:4739 -> xxx.yyy.1.3:20168 SYN ******S* May 12 13:26:59 209.196.128.253:4740 -> xxx.yyy.1.4:20168 SYN ******S* May 12 13:27:02 209.196.128.253:4741 -> xxx.yyy.1.5:20168 SYN ******S* May 12 13:27:02 209.196.128.253:4742 -> xxx.yyy.1.6:20168 SYN ******S* May 12 13:27:02 209.196.128.253:4743 -> xxx.yyy.1.7:20168 SYN ******S* May 12 13:27:02 209.196.128.253:4744 -> xxx.yyy.1.8:20168 SYN ******S* [...] May 12 13:38:41 209.196.128.253:2557 -> xxx.yyy.255.248:20168 SYN ******S* May 12 13:38:41 209.196.128.253:2550 -> xxx.yyy.255.241:20168 SYN ******S* May 12 13:38:41 209.196.128.253:2555 -> xxx.yyy.255.246:20168 SYN ******S* May 12 13:38:41 209.196.128.253:2551 -> xxx.yyy.255.242:20168 SYN ******S* May 12 13:38:41 209.196.128.253:2562 -> xxx.yyy.255.253:20168 SYN ******S* May 12 13:38:41 209.196.128.253:2561 -> xxx.yyy.255.252:20168 SYN ******S* May 12 13:38:41 209.196.128.253:2560 -> xxx.yyy.255.251:20168 SYN ******S* May 12 13:38:41 209.196.128.253:2563 -> xxx.yyy.255.254:20168 SYN ******S* 67636 May 12 11:20:18 192.100.165.68:3592 -> xxx.yyy.1.1:4000 SYN ******S* May 12 11:20:18 192.100.165.68:3593 -> xxx.yyy.1.2:4000 SYN ******S* May 12 11:20:20 192.100.165.68:3594 -> xxx.yyy.1.3:4000 SYN ******S* May 12 11:20:20 192.100.165.68:3595 -> xxx.yyy.1.4:4000 SYN ******S* May 12 11:20:17 192.100.165.68:3596 -> xxx.yyy.1.5:4000 SYN ******S* May 12 11:20:20 192.100.165.68:3597 -> xxx.yyy.1.6:4000 SYN ******S* May 12 11:20:20 192.100.165.68:3598 -> xxx.yyy.1.7:4000 SYN ******S* May 12 11:20:20 192.100.165.68:3600 -> xxx.yyy.1.9:4000 SYN ******S* [...] May 12 11:32:18 192.100.165.68:2117 -> xxx.yyy.255.147:4000 SYN ******S* May 12 11:32:18 192.100.165.68:2118 -> xxx.yyy.255.148:4000 SYN ******S* May 12 11:32:18 192.100.165.68:2132 -> xxx.yyy.255.162:4000 SYN ******S* May 12 11:32:18 192.100.165.68:2148 -> xxx.yyy.255.178:4000 SYN ******S* May 12 11:32:18 192.100.165.68:2144 -> xxx.yyy.255.174:4000 SYN ******S* May 12 11:32:18 192.100.165.68:2146 -> xxx.yyy.255.176:4000 SYN ******S* May 12 11:32:18 192.100.165.68:2194 -> xxx.yyy.255.224:4000 SYN ******S* May 12 11:32:18 192.100.165.68:2200 -> xxx.yyy.255.230:4000 SYN ******S* 67455 May 12 11:37:06 213.180.193.68:30365 -> xxx.yyy.17.24:1080 SYN ******S* May 12 11:37:06 213.180.193.68:30366 -> xxx.yyy.17.24:1180 SYN ******S* May 12 11:37:06 213.180.193.68:30391 -> xxx.yyy.17.24:1075 SYN ******S* May 12 11:37:06 213.180.193.68:30389 -> xxx.yyy.17.24:80 SYN ******S* May 12 11:37:06 213.180.193.68:30390 -> xxx.yyy.17.24:81 SYN ******S* May 12 11:37:06 213.180.193.68:30392 -> xxx.yyy.17.24:1182 SYN ******S* May 12 11:37:06 213.180.193.68:30393 -> xxx.yyy.17.24:3128 SYN ******S* May 12 11:37:06 213.180.193.68:30394 -> xxx.yyy.17.24:4480 SYN ******S* [...] May 12 21:19:36 213.180.193.68:44552 -> xxx.yyy.239.99:6006 SYN ******S* May 12 21:19:36 213.180.193.68:44552 -> xxx.yyy.239.99:6043 SYN ******S* May 12 21:19:36 213.180.193.68:44552 -> xxx.yyy.239.99:12346 SYN ******S* May 12 21:19:36 213.180.193.68:44552 -> xxx.yyy.239.99:6019 SYN ******S* May 12 21:19:36 213.180.193.68:44552 -> xxx.yyy.239.99:6025 SYN ******S* May 12 21:19:36 213.180.193.68:44552 -> xxx.yyy.239.99:6008 SYN ******S* May 12 21:19:36 213.180.193.68:44552 -> xxx.yyy.239.99:6046 SYN ******S* May 12 21:19:36 213.180.193.68:44552 -> xxx.yyy.239.99:6045 SYN ******S* May 12 21:19:36 213.180.193.68:44552 -> xxx.yyy.239.99:6041 SYN ******S* 53912 May 12 00:00:56 209.63.202.201:3406 -> xxx.yyy.71.190:2745 SYN ******S* May 12 00:00:57 209.63.202.201:3528 -> xxx.yyy.73.82:2745 SYN ******S* May 12 00:01:00 209.63.202.201:3685 -> xxx.yyy.12.76:2745 SYN ******S* May 12 00:00:57 209.63.202.201:3128 -> xxx.yyy.17.187:2745 SYN ******S* May 12 00:01:01 209.63.202.201:3807 -> xxx.yyy.216.22:2745 SYN ******S* May 12 00:01:01 209.63.202.201:3818 -> xxx.yyy.158.11:2745 SYN ******S* May 12 00:00:58 209.63.202.201:3221 -> xxx.yyy.171.45:2745 SYN ******S* May 12 00:01:02 209.63.202.201:3406 -> xxx.yyy.71.190:2745 SYN ******S* [...] May 12 23:59:46 209.63.202.201:2882 -> xxx.yyy.193.237:2745 SYN ******S* May 12 23:59:48 209.63.202.201:2441 -> xxx.yyy.200.10:2745 SYN ******S* May 12 23:59:50 209.63.202.201:3267 -> xxx.yyy.251.179:2745 SYN ******S* May 12 23:59:53 209.63.202.201:3267 -> xxx.yyy.251.179:2745 SYN ******S* May 12 23:59:55 209.63.202.201:2882 -> xxx.yyy.193.237:2745 SYN ******S* May 12 23:59:55 209.63.202.201:3781 -> xxx.yyy.186.22:2745 SYN ******S* May 12 23:59:58 209.63.202.201:3781 -> xxx.yyy.186.22:2745 SYN ******S* May 12 23:59:59 209.63.202.201:3267 -> xxx.yyy.251.179:2745 SYN ******S* 47225 May 12 02:01:20 61.54.225.98:4929 -> xxx.yyy.1.0:901 SYN ******S* May 12 02:01:23 61.54.225.98:4961 -> xxx.yyy.1.2:901 SYN ******S* May 12 02:01:22 61.54.225.98:4963 -> xxx.yyy.1.4:901 SYN ******S* May 12 02:01:22 61.54.225.98:4965 -> xxx.yyy.1.6:901 SYN ******S* May 12 02:01:22 61.54.225.98:4964 -> xxx.yyy.1.5:901 SYN ******S* May 12 02:01:22 61.54.225.98:4966 -> xxx.yyy.1.7:901 SYN ******S* May 12 02:01:23 61.54.225.98:4960 -> xxx.yyy.1.1:901 SYN ******S* May 12 02:01:22 61.54.225.98:4968 -> xxx.yyy.1.9:901 SYN ******S* [...] May 12 03:51:16 61.54.225.98:4946 -> xxx.yyy.254.250:901 SYN ******S* May 12 03:51:16 61.54.225.98:4944 -> xxx.yyy.254.248:901 SYN ******S* May 12 03:51:16 61.54.225.98:4947 -> xxx.yyy.254.251:901 SYN ******S* May 12 03:51:16 61.54.225.98:4949 -> xxx.yyy.254.253:901 SYN ******S* May 12 03:51:16 61.54.225.98:4951 -> xxx.yyy.254.255:901 SYN ******S* May 12 03:51:16 61.54.225.98:4941 -> xxx.yyy.254.245:901 SYN ******S* May 12 03:51:16 61.54.225.98:4943 -> xxx.yyy.254.247:901 SYN ******S* May 12 03:51:16 61.54.225.98:4948 -> xxx.yyy.254.252:901 SYN ******S* May 12 03:51:16 61.54.225.98:4950 -> xxx.yyy.254.254:901 SYN ******S* 46009 May 12 19:30:40 63.201.33.110:2217 -> xxx.yyy.1.0:139 SYN ******S* May 12 19:30:40 63.201.33.110:2218 -> xxx.yyy.1.1:139 SYN ******S* May 12 19:30:40 63.201.33.110:2219 -> xxx.yyy.1.2:139 SYN ******S* May 12 19:30:40 63.201.33.110:2220 -> xxx.yyy.1.3:139 SYN ******S* May 12 19:30:40 63.201.33.110:2221 -> xxx.yyy.1.4:139 SYN ******S* May 12 19:30:40 63.201.33.110:2222 -> xxx.yyy.1.5:139 SYN ******S* May 12 19:30:40 63.201.33.110:2223 -> xxx.yyy.1.6:139 SYN ******S* May 12 19:30:40 63.201.33.110:2224 -> xxx.yyy.1.7:139 SYN ******S* [...] May 12 21:19:46 63.201.33.110:2917 -> xxx.yyy.254.248:139 SYN ******S* May 12 21:19:46 63.201.33.110:2918 -> xxx.yyy.254.249:139 SYN ******S* May 12 21:19:46 63.201.33.110:2919 -> xxx.yyy.254.250:139 SYN ******S* May 12 21:19:46 63.201.33.110:2920 -> xxx.yyy.254.251:139 SYN ******S* May 12 21:19:46 63.201.33.110:2921 -> xxx.yyy.254.252:139 SYN ******S* May 12 21:19:46 63.201.33.110:2922 -> xxx.yyy.254.253:139 SYN ******S* May 12 21:19:46 63.201.33.110:2923 -> xxx.yyy.254.254:139 SYN ******S* May 12 21:19:46 63.201.33.110:2924 -> xxx.yyy.254.255:139 SYN ******S* 44340 May 12 13:41:16 63.242.166.148:3618 -> xxx.yyy.1.1:4899 SYN ******S* May 12 13:41:16 63.242.166.148:3619 -> xxx.yyy.1.2:4899 SYN ******S* May 12 13:41:15 63.242.166.148:3620 -> xxx.yyy.1.3:4899 SYN ******S* May 12 13:41:15 63.242.166.148:3621 -> xxx.yyy.1.4:4899 SYN ******S* May 12 13:41:15 63.242.166.148:3622 -> xxx.yyy.1.5:4899 SYN ******S* May 12 13:41:15 63.242.166.148:3623 -> xxx.yyy.1.6:4899 SYN ******S* May 12 13:41:15 63.242.166.148:3624 -> xxx.yyy.1.7:4899 SYN ******S* May 12 13:41:15 63.242.166.148:3625 -> xxx.yyy.1.8:4899 SYN ******S* [...] May 12 13:44:34 63.242.166.148:4146 -> xxx.yyy.255.248:4899 SYN ******S* May 12 13:44:34 63.242.166.148:4147 -> xxx.yyy.255.249:4899 SYN ******S* May 12 13:44:34 63.242.166.148:4149 -> xxx.yyy.255.250:4899 SYN ******S* May 12 13:44:34 63.242.166.148:4153 -> xxx.yyy.255.251:4899 SYN ******S* May 12 13:44:34 63.242.166.148:4157 -> xxx.yyy.255.252:4899 SYN ******S* May 12 13:44:34 63.242.166.148:4160 -> xxx.yyy.255.253:4899 SYN ******S* May 12 13:44:34 63.242.166.148:4161 -> xxx.yyy.255.254:4899 SYN ******S* May 12 13:44:34 63.242.166.148:3108 -> xxx.yyy.253.155:4899 SYN ******S* 42126 May 12 01:01:49 203.87.137.178:4313 -> xxx.yyy.1.1:1433 SYN ******S* May 12 01:01:46 203.87.137.178:4314 -> xxx.yyy.1.2:1433 SYN ******S* May 12 01:01:46 203.87.137.178:4315 -> xxx.yyy.1.3:1433 SYN ******S* May 12 01:01:46 203.87.137.178:4317 -> xxx.yyy.1.5:1433 SYN ******S* May 12 01:01:46 203.87.137.178:4318 -> xxx.yyy.1.6:1433 SYN ******S* May 12 01:01:47 203.87.137.178:4319 -> xxx.yyy.1.7:1433 SYN ******S* May 12 01:01:47 203.87.137.178:4323 -> xxx.yyy.1.11:1433 SYN ******S* May 12 01:01:50 203.87.137.178:4324 -> xxx.yyy.1.12:1433 SYN ******S* [...] May 12 01:13:36 203.87.137.178:2998 -> xxx.yyy.255.228:1433 SYN ******S* May 12 01:13:36 203.87.137.178:2993 -> xxx.yyy.255.223:1433 SYN ******S* May 12 01:13:36 203.87.137.178:3007 -> xxx.yyy.255.237:1433 SYN ******S* May 12 01:13:36 203.87.137.178:3004 -> xxx.yyy.255.234:1433 SYN ******S* May 12 01:13:36 203.87.137.178:3005 -> xxx.yyy.255.235:1433 SYN ******S* May 12 01:13:36 203.87.137.178:3003 -> xxx.yyy.255.233:1433 SYN ******S* May 12 01:13:36 203.87.137.178:3017 -> xxx.yyy.255.247:1433 SYN ******S* May 12 01:13:36 203.87.137.178:3018 -> xxx.yyy.255.248:1433 SYN ******S* 37340 May 12 00:00:03 220.168.28.35:46865 -> xxx.yyy.144.231:1025 SYN ******S* May 12 00:00:04 220.168.28.35:23463 -> xxx.yyy.70.130:3127 SYN ******S* May 12 00:00:04 220.168.28.35:8820 -> xxx.yyy.70.130:1025 SYN ******S* May 12 00:00:04 220.168.28.35:23466 -> xxx.yyy.70.130:6129 SYN ******S* May 12 00:00:04 220.168.28.35:64816 -> xxx.yyy.70.130:80 SYN ******S* May 12 00:00:04 220.168.28.35:1065 -> xxx.yyy.133.237:2745 SYN ******S* May 12 00:00:07 220.168.28.35:1748 -> xxx.yyy.239.91:2745 SYN ******S* May 12 00:00:07 220.168.28.35:65054 -> xxx.yyy.72.167:2745 SYN ******S* [...] May 12 23:55:50 220.168.28.35:22931 -> xxx.yyy.105.56:6129 SYN ******S* May 12 23:55:50 220.168.28.35:7118 -> xxx.yyy.145.208:2745 SYN ******S* May 12 23:55:50 220.168.28.35:7204 -> xxx.yyy.133.189:2745 SYN ******S* May 12 23:55:51 220.168.28.35:8912 -> xxx.yyy.209.13:6129 SYN ******S* May 12 23:55:51 220.168.28.35:38881 -> xxx.yyy.209.13:5000 SYN ******S* May 12 23:55:51 220.168.28.35:9084 -> xxx.yyy.213.232:2745 SYN ******S* May 12 23:55:52 220.168.28.35:9170 -> xxx.yyy.160.215:6129 SYN ******S* May 12 23:55:55 220.168.28.35:41743 -> xxx.yyy.13.159:6129 SYN ******S* May 12 23:55:55 220.168.28.35:9170 -> xxx.yyy.160.215:6129 SYN ******S* 30630 May 12 20:09:59 64.151.57.68:4867 -> xxx.yyy.1.2:445 SYN ******S* May 12 20:09:59 64.151.57.68:4868 -> xxx.yyy.1.3:445 SYN ******S* May 12 20:09:59 64.151.57.68:4869 -> xxx.yyy.1.4:445 SYN ******S* May 12 20:09:59 64.151.57.68:4870 -> xxx.yyy.1.5:445 SYN ******S* May 12 20:09:59 64.151.57.68:4871 -> xxx.yyy.1.6:445 SYN ******S* May 12 20:09:59 64.151.57.68:4872 -> xxx.yyy.1.7:445 SYN ******S* May 12 20:09:59 64.151.57.68:4874 -> xxx.yyy.1.8:445 SYN ******S* May 12 20:09:59 64.151.57.68:4875 -> xxx.yyy.1.9:445 SYN ******S* [...] May 12 20:57:49 64.151.57.68:2374 -> xxx.yyy.95.161:445 SYN ******S* May 12 20:57:49 64.151.57.68:2422 -> xxx.yyy.95.209:445 SYN ******S* May 12 20:57:49 64.151.57.68:2371 -> xxx.yyy.95.158:445 SYN ******S* May 12 20:57:49 64.151.57.68:2368 -> xxx.yyy.95.155:445 SYN ******S* May 12 20:57:49 64.151.57.68:2365 -> xxx.yyy.95.152:445 SYN ******S* May 12 20:57:49 64.151.57.68:2429 -> xxx.yyy.95.216:445 SYN ******S* May 12 20:57:49 64.151.57.68:2426 -> xxx.yyy.95.213:445 SYN ******S* May 12 20:57:49 64.151.57.68:2454 -> xxx.yyy.95.241:445 SYN ******S* 30380 May 12 15:22:57 80.239.50.242:3240 -> xxx.yyy.1.0:5554 SYN ******S* May 12 15:22:57 80.239.50.242:3241 -> xxx.yyy.1.1:5554 SYN ******S* May 12 15:22:57 80.239.50.242:3242 -> xxx.yyy.1.2:5554 SYN ******S* May 12 15:22:57 80.239.50.242:3243 -> xxx.yyy.1.3:5554 SYN ******S* May 12 15:22:57 80.239.50.242:3244 -> xxx.yyy.1.4:5554 SYN ******S* May 12 15:22:57 80.239.50.242:3245 -> xxx.yyy.1.5:5554 SYN ******S* May 12 15:22:57 80.239.50.242:3199 -> xxx.yyy.1.9:5554 SYN ******S* May 12 15:22:57 80.239.50.242:3201 -> xxx.yyy.1.11:5554 SYN ******S* [...] May 12 15:23:43 80.239.50.242:3200 -> xxx.yyy.255.240:5554 SYN ******S* May 12 15:23:43 80.239.50.242:3201 -> xxx.yyy.255.241:5554 SYN ******S* May 12 15:23:43 80.239.50.242:3202 -> xxx.yyy.255.242:5554 SYN ******S* May 12 15:23:43 80.239.50.242:3203 -> xxx.yyy.255.243:5554 SYN ******S* May 12 15:23:43 80.239.50.242:3206 -> xxx.yyy.255.246:5554 SYN ******S* May 12 15:23:43 80.239.50.242:3207 -> xxx.yyy.255.247:5554 SYN ******S* May 12 15:23:43 80.239.50.242:3208 -> xxx.yyy.255.248:5554 SYN ******S* May 12 15:23:43 80.239.50.242:3209 -> xxx.yyy.255.249:5554 SYN ******S* May 12 15:23:43 80.239.50.242:3210 -> xxx.yyy.255.250:5554 SYN ******S* 20612 [...] 18397 May 12 03:30:08 164.58.6.110:1626 -> xxx.yyy.1.1:1023 SYN ******S* May 12 03:30:08 164.58.6.110:1627 -> xxx.yyy.1.2:1023 SYN ******S* May 12 03:30:10 164.58.6.110:1628 -> xxx.yyy.1.3:1023 SYN ******S* May 12 03:30:10 164.58.6.110:1629 -> xxx.yyy.1.4:1023 SYN ******S* May 12 03:30:10 164.58.6.110:1630 -> xxx.yyy.1.5:1023 SYN ******S* May 12 03:30:10 164.58.6.110:1631 -> xxx.yyy.1.6:1023 SYN ******S* May 12 03:30:10 164.58.6.110:1632 -> xxx.yyy.1.7:1023 SYN ******S* May 12 03:30:10 164.58.6.110:1633 -> xxx.yyy.1.8:1023 SYN ******S* [...] May 12 03:40:50 164.58.6.110:2367 -> xxx.yyy.234.185:1023 SYN ******S* May 12 03:40:50 164.58.6.110:2366 -> xxx.yyy.234.184:1023 SYN ******S* May 12 03:40:50 164.58.6.110:2364 -> xxx.yyy.234.182:1023 SYN ******S* May 12 03:40:50 164.58.6.110:2361 -> xxx.yyy.234.179:1023 SYN ******S* May 12 03:40:50 164.58.6.110:2363 -> xxx.yyy.234.181:1023 SYN ******S* May 12 03:40:50 164.58.6.110:2362 -> xxx.yyy.234.180:1023 SYN ******S* May 12 03:40:50 164.58.6.110:2640 -> xxx.yyy.235.203:1023 SYN ******S* May 12 03:40:50 164.58.6.110:2641 -> xxx.yyy.235.204:1023 SYN ******S* 16719 May 12 01:44:24 80.116.91.241:22002 -> xxx.yyy.1.0:3127 SYN ******S* May 12 01:44:24 80.116.91.241:22002 -> xxx.yyy.1.0:1080 SYN ******S* May 12 01:44:24 80.116.91.241:22002 -> xxx.yyy.1.0:10080 SYN ******S* May 12 01:44:24 80.116.91.241:22002 -> xxx.yyy.1.0:3128 SYN ******S* May 12 01:44:25 80.116.91.241:22002 -> xxx.yyy.1.1:3127 SYN ******S* May 12 01:44:25 80.116.91.241:22002 -> xxx.yyy.1.1:1080 SYN ******S* May 12 01:44:25 80.116.91.241:22002 -> xxx.yyy.1.1:10080 SYN ******S* May 12 01:44:25 80.116.91.241:22002 -> xxx.yyy.1.1:3128 SYN ******S* [...] May 12 02:42:07 80.116.91.241:22002 -> xxx.yyy.32.254:3127 SYN ******S* May 12 02:42:07 80.116.91.241:22002 -> xxx.yyy.32.254:1080 SYN ******S* May 12 02:42:07 80.116.91.241:22002 -> xxx.yyy.32.254:10080 SYN ******S* May 12 02:42:07 80.116.91.241:22002 -> xxx.yyy.32.254:3128 SYN ******S* May 12 02:42:07 80.116.91.241:22002 -> xxx.yyy.32.255:3127 SYN ******S* May 12 02:42:07 80.116.91.241:22002 -> xxx.yyy.32.255:1080 SYN ******S* May 12 02:42:07 80.116.91.241:22002 -> xxx.yyy.32.255:10080 SYN ******S* May 12 02:42:07 80.116.91.241:22002 -> xxx.yyy.32.255:3128 SYN ******S* 7837 May 12 00:00:32 66.190.44.41:1619 -> xxx.yyy.73.153:2745 SYN ******S* May 12 00:00:33 66.190.44.41:1626 -> xxx.yyy.158.102:2745 SYN ******S* May 12 00:00:33 66.190.44.41:1629 -> xxx.yyy.239.220:2745 SYN ******S* May 12 00:00:31 66.190.44.41:1525 -> xxx.yyy.66.219:2745 SYN ******S* May 12 00:00:37 66.190.44.41:1701 -> xxx.yyy.196.25:2745 SYN ******S* May 12 00:00:37 66.190.44.41:1753 -> xxx.yyy.171.54:2745 SYN ******S* May 12 00:00:38 66.190.44.41:1619 -> xxx.yyy.73.153:2745 SYN ******S* May 12 00:00:39 66.190.44.41:1626 -> xxx.yyy.158.102:2745 SYN ******S* [...] May 12 23:59:25 66.190.44.41:2432 -> xxx.yyy.228.105:1025 SYN ******S* May 12 23:59:24 66.190.44.41:2466 -> xxx.yyy.69.244:2745 SYN ******S* May 12 23:59:27 66.190.44.41:2466 -> xxx.yyy.69.244:2745 SYN ******S* May 12 23:59:31 66.190.44.41:2415 -> xxx.yyy.231.171:2745 SYN ******S* May 12 23:59:31 66.190.44.41:2420 -> xxx.yyy.129.196:1025 SYN ******S* May 12 23:59:31 66.190.44.41:2418 -> xxx.yyy.129.196:2745 SYN ******S* May 12 23:59:31 66.190.44.41:2432 -> xxx.yyy.228.105:1025 SYN ******S* May 12 23:59:33 66.190.44.41:2466 -> xxx.yyy.69.244:2745 SYN ******S* 7597 May 12 07:43:21 212.205.246.142:3867 -> xxx.yyy.10.229:1433 SYN ******S* May 12 07:43:21 212.205.246.142:4156 -> xxx.yyy.10.230:1433 SYN ******S* May 12 07:43:21 212.205.246.142:4157 -> xxx.yyy.10.231:1433 SYN ******S* May 12 07:43:21 212.205.246.142:4169 -> xxx.yyy.10.232:1433 SYN ******S* May 12 07:43:21 212.205.246.142:4178 -> xxx.yyy.10.233:1433 SYN ******S* May 12 07:43:21 212.205.246.142:4181 -> xxx.yyy.10.235:1433 SYN ******S* May 12 07:43:21 212.205.246.142:4179 -> xxx.yyy.10.234:1433 SYN ******S* May 12 07:43:21 212.205.246.142:4183 -> xxx.yyy.10.236:1433 SYN ******S* [...] May 12 08:03:04 212.205.246.142:1662 -> xxx.yyy.32.117:1433 SYN ******S* May 12 08:03:04 212.205.246.142:1908 -> xxx.yyy.32.178:1433 SYN ******S* May 12 08:03:04 212.205.246.142:1909 -> xxx.yyy.32.179:1433 SYN ******S* May 12 08:03:04 212.205.246.142:1910 -> xxx.yyy.32.180:1433 SYN ******S* May 12 08:03:04 212.205.246.142:1687 -> xxx.yyy.32.122:1433 SYN ******S* May 12 08:03:04 212.205.246.142:1846 -> xxx.yyy.32.156:1433 SYN ******S* May 12 08:03:04 212.205.246.142:1911 -> xxx.yyy.32.181:1433 SYN ******S* May 12 08:03:04 212.205.246.142:1912 -> xxx.yyy.32.182:1433 SYN ******S* 6700 May 12 07:36:00 66.222.224.166:2032 -> xxx.yyy.73.18:6129 SYN ******S* May 12 07:36:00 66.222.224.166:2033 -> xxx.yyy.73.18:139 SYN ******S* May 12 07:36:00 66.222.224.166:2034 -> xxx.yyy.73.18:5000 SYN ******S* May 12 07:36:01 66.222.224.166:2342 -> xxx.yyy.134.101:6129 SYN ******S* May 12 07:36:01 66.222.224.166:2343 -> xxx.yyy.134.101:139 SYN ******S* May 12 07:36:01 66.222.224.166:2344 -> xxx.yyy.134.101:5000 SYN ******S* May 12 07:35:59 66.222.224.166:2374 -> xxx.yyy.198.228:6129 SYN ******S* May 12 07:35:59 66.222.224.166:2375 -> xxx.yyy.198.228:139 SYN ******S* [...] May 12 08:57:43 66.222.224.166:3754 -> xxx.yyy.75.216:139 SYN ******S* May 12 08:57:44 66.222.224.166:3790 -> xxx.yyy.174.75:6129 SYN ******S* May 12 08:57:44 66.222.224.166:3809 -> xxx.yyy.241.25:6129 SYN ******S* May 12 08:57:44 66.222.224.166:3810 -> xxx.yyy.241.25:139 SYN ******S* May 12 08:57:44 66.222.224.166:3811 -> xxx.yyy.241.25:5000 SYN ******S* May 12 08:57:44 66.222.224.166:3437 -> xxx.yyy.74.142:6129 SYN ******S* May 12 08:57:45 66.222.224.166:3809 -> xxx.yyy.241.25:6129 SYN ******S* May 12 08:57:45 66.222.224.166:3753 -> xxx.yyy.75.216:6129 SYN ******S* May 12 08:57:45 66.222.224.166:3754 -> xxx.yyy.75.216:139 SYN ******S* 6590 -- - Ken =========================================================================== Ken Connelly (KC152) Systems and Operations Manager, ITS - Network Services University of Northern Iowa Cedar Falls, IA 50614-0121 email: Ken.Connelly@xxxxxxx phone: (319) 273-5850 fax: (319) 273-7373 _______________________________________________ Intrusions mailing list Intrusions@xxxxxxxxxxxxxx http://www.dshield.org/mailman/listinfo/intrusions |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Agobot WebDAV exploit crashing patched NT4 IIS: 00037, Jon Hedlund |
|---|---|
| Next by Date: | repeated entries with multiple '&'s in URI query of GETs in IIS l ogs: 00037, Weiler, Jim |
| Previous by Thread: | [LOGS] Summary of large-scale portscanning detectsi: 00037, Ken . Connelly |
| Next by Thread: | [LOGS] Summary of large-scale portscanning detects: 00037, Ken . Connelly |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |