portscan for 2036 80

Joakim Berge <[email protected]> Thu, 20 Oct 2005 13:21:49 +0200
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
I observe many scans for port 2036 and "2036 80".
Why 80 shows up, i don't know. but port 2036 are being used by Novell's RConJ.
The scan seems to be from a large botnet, across the world.  They have
only targeted one ip, and it doesn't respond to those ports.

I cant find any info on this on the net.
Is it the tryout of a new worm? Anyone seen any of this activity?
--
Joakim Berge
Tlf. +47 93489696
MSN. [email protected]

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions