Security Incidents mailing list archives

Another odd UDP scan - new trojan?


From: neil.long () COMPUTING-SERVICES OXFORD AC UK (Neil Long)
Date: Thu, 18 May 2000 11:32:52 +0100


Hi

We just had a report which is unusual -

UDP ports 33448 through 33453

Scanning one of our net blocks but rolling the loop on the 3rd octet and
throttled down to one every  second or so. Src port number constant per dest
host but then changing on the next target ip.

Src IP is in an Exodus net block - 64.41.164.54

Anyone else seeing this or know what they are looking for? All attempts were
fruitless, just curious.

Cheers
Neil


Current thread: