"Deja Vu", IKE then SMTP connect scan

"Patrick Nolan" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <030401c50593$6f8a6780$0500a8c0@sr52>
fwiw and for "Mr. Smith"'s scan book ( ; ^ )

Timing - 3 seconds between Port 500 probe and Port 25 connection. Consistent 
enough for

me. ymmv.

Date  Time Action Dport Source  Dest Pro     Sport
#1
27-Jan-05 3:14:06 Drop 500 66.92.125.186 E-Mail  udp 500
27-Jan-05 3:14:09 Accept 25 66.92.125.186 E-Mail  tcp 9570

#2
27-Jan-05 5:07:51 Drop 500 24.16.138.185 E-Mail  udp 500
27-Jan-05 5:07:54 Accept 25 24.16.138.185 E-Mail  tcp 33629

#3
28-Jan-05 8:53:36 Drop 500 220.169.113.128 E-Mail  udp 500
28-Jan-05 8:53:39 Accept 25 220.169.113.128 E-Mail  tcp 4794

28-Jan-05 8:54:39 Drop 500 220.169.113.128 E-Mail  udp 500

28-Jan-05 9:02:42 Drop 500 220.169.113.128 E-Mail  udp 500
28-Jan-05 9:02:45 Accept 25 220.169.113.128 E-Mail  tcp 3757
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

#1

Date:                                      27Jan2005
Time:                                     3:14:06
Action:                                    Drop
Service:                                 IKE (500)
Source: 
dsl092-125-186.nyc2.dsl.speakeasy.net

(66.92.125.186)
Destination:                           E-Mail  (Internet IP)
Protocol:                                udp
Source Port:                           IKE (500)

Date:                                      27Jan2005
Time:                                     3:14:09
Action:                                    Accept
Service:                                 smtp (25)
Source: 
dsl092-125-186.nyc2.dsl.speakeasy.net

(66.92.125.186)
Destination:                           E-Mail  (Internet IP)
Protocol:                                tcp
Source Port:                           9570
XlateDst:                                Next hop
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

#2

Date:                                      27Jan2005
Time:                                     5:07:51
Action:                                    Drop
Service:                                 IKE (500)
Source:                                  c-24-16-138-185.client.comcast.net

(24.16.138.185)
Destination:                           E-Mail  (Internet IP)
Protocol:                                udp
Source Port:                           IKE (500)

Date:                                      27Jan2005
Time:                                     5:07:54
Action:                                    Accept
Service:                                 smtp (25)
Source:                                  c-24-16-138-185.client.comcast.net

(24.16.138.185)
Destination:                           E-Mail  (Internet IP)
Protocol:                                tcp
Source Port:                           33629
XlateDst:                                Next hop
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

#3

Date:                                      28Jan2005
Time:                                     8:53:36
Action:                                    Drop
Service:                                 IKE (500)
Source:                                  220.169.113.128
Destination:                           E-Mail  (Internet IP)
Protocol:                                udp
Rule:                                      21
Source Port:                           IKE (500)

Date:                                      28Jan2005
Time:                                     8:53:39
Product:                                 VPN-1 & FireWall-1
Action:                                    Accept
Service:                                 smtp (25)
Source:                                  220.169.113.128
Destination:                           E-Mail  (Internet IP)
Protocol:                                tcp
Source Port:                           4794
XlateDst:                                Next hop

Date:                                      28Jan2005
Time:                                     8:54:39
Action:                                    Drop
Service:                                 IKE (500)
Source:                                  220.169.113.128
Destination:                           E-Mail  (Internet IP)
Protocol:                                udp
Source Port:                           IKE (500)

Date:                                      28Jan2005
Time:                                     9:02:42
Action:                                    Drop
Service:                                 IKE (500)
Source:                                  220.169.113.128
Destination:                           E-Mail  (Internet IP)
Protocol:                                udp
Source Port:                           IKE (500)

Date:                                      28Jan2005
Time:                                     9:02:45
Action:                                    Accept
Service:                                 smtp (25)
Source:                                  220.169.113.128
Destination:                           E-Mail  (Internet IP)
Protocol:                                tcp
Source Port:                           3757
XlateDst:                                Next hop
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx


DShield

IP Address: 220.169.113.128
HostName: 220.169.113.128
DShield Profile: Country:   CN
Contact E-mail: [email protected]
AS Number: 4134
Total Records against IP:  2378
Number of targets:  147
Date Range: 2005-01-21 to 2005-01-28
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

The scan that stands out on January 17/18/19 targeted Port 500 only, 
"scanner" info

below.

http://isc.sans.org/port_details.php?port=500&repax=1&tarax=2&srcax=2&percent=N&days=40

&Redraw=Submit+Query

Source IP that swept was;
Dshield;
IP Address: 207.44.194.25
HostName: h9.plesklogin.net
DShield Profile: Country:   US
Contact E-mail: [email protected]
AS Number: 13749
Total Records against IP:  568675
Number of targets:  63266
Date Range: 2004-12-20 to 2005-01-23



_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.