portscan for 2036 80
Joakim Berge <[email protected]> Thu, 20 Oct 2005 13:21:49 +0200
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
I observe many scans for port 2036 and "2036 80". Why 80 shows up, i don't know. but port 2036 are being used by Novell's RConJ. The scan seems to be from a large botnet, across the world. They have only targeted one ip, and it doesn't respond to those ports. I cant find any info on this on the net. Is it the tryout of a new worm? Anyone seen any of this activity? -- Joakim Berge Tlf. +47 93489696 MSN. [email protected] _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions