Re: Who is looking for port 2036?

Tillmann Werner <[email protected]>
Newsgroups gmane.comp.security.incidents
Message-ID <[email protected]>
Joakim,

> The scan seems to be from a large botnet, across the world.

What makes you believe the attack's origin is a botnet?

> They have only targeted one ip, and it doesn't respond to those ports.

Your samples only showed port 2036/tcp on a very low frequency. Is this 
representative for a longer period? What is the percentage of port 80/tcp 
packets?

> Is it the tryout of a new worm?

Unlikely, if it only targets a single ip address which does not respond. Http 
might be used as destination port for such packets are likely to go through 
firewalls.

If you are interested in furhter investigation, you could run netcat on the 
attacked host to see if connection establishment goes on and if there arrives 
any data.

Tillmann
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.