Security Basics mailing list archives

Repeated Port Scan


From: compguruman () mail comcast net
Date: Wed, 25 Jun 2003 17:30:47 -0400

I've been getting port scans from the same IP address for 3 days. It is not scanning continuously but will usually scan me every 2 hours for a few hours. When I do a whois on the address it doesn't give much information on who to contact about abuse. I'm thinking that the computer scanning me has been compromised and is looking for other computers to infect. The source port is random but the local port is not. It scans to see if ports 1075, 3128, 4588, 6588, and 8080 are open. I ran retina against the machine and its running a default install of Apache without much anything configured. The Sequence # of the packets are always 666666 and all have the SYN flag set. Does anybody know of any worms or Trojans that scan for these ports and have these features? Also, if whois doesn't give much information how can I find out who to contact about this? I've attached some of the packets that I've captured, along with the whois information. Any help is appreciated.

TIA

Attachment: Capture.txt
Description:

---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
     
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
          
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------

Current thread: