Re: Who is looking for port 2036?
Tillmann Werner <[email protected]>
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Message-ID | <[email protected]> |
Joakim, > The scan seems to be from a large botnet, across the world. What makes you believe the attack's origin is a botnet? > They have only targeted one ip, and it doesn't respond to those ports. Your samples only showed port 2036/tcp on a very low frequency. Is this representative for a longer period? What is the percentage of port 80/tcp packets? > Is it the tryout of a new worm? Unlikely, if it only targets a single ip address which does not respond. Http might be used as destination port for such packets are likely to go through firewalls. If you are interested in furhter investigation, you could run netcat on the attacked host to see if connection establishment goes on and if there arrives any data. Tillmann