Re: UDP traffic on port 48864

"James C Slora Jr" <[email protected]> Tue, 14 Jun 2005 09:28:51 -0400
Newsgroups gmane.comp.security.intrusions
Organization PHR+A, pc
Message-ID <[email protected]>
Andrew Daviel wrote Monday, June 13, 2005 6:42 PM

>  I've been seeing UDP traffic sent to a host here on port 48864; it seems
to all (or mostly) targetted at one particular host, which does not seem to
respond (apart from maybe ICMP unreachable). It's from random places on the
net (including residential, like P2P), but the packets are quite small
(15-500 bytes) and don't seem to have any ASCII content.

Packets would be nice.

Some trojans calculate the target port from the target IP address, so the
port might not be any direct clue. Some examples of what may be similar
traffic:

http://seclists.org/lists/incidents/2004/Apr/0019.html



_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions