massive scans on 5634/tcp

From: Dominik Samuelis (checkpoint-fw1at_private-darmstadt.de)
Date: Wed Jun 27 2001 - 12:15:08 PDT

  • Next message: Bryan Allerdice: "Re: Threat mail from russia (followup)"

    Hello,
    
    Today, I had massive port scans on port 5634/tcp (15619 packets on my single
    box as of now, coming from 255 distinct sources). Any clues what this could
    be ?
    
    Packet log: input DENY ppp0 PROTO=6 us.cable.modem:3247 217.0.224.94:5634
    L=44 S=0x00 I=1 F=0x4000 T=110 SYN (#9)
    
    TIA
    Dominik
    
    
    ----------------------------------------------------------------------------
    
    
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see:
    
    http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Jun 27 2001 - 23:27:18 PDT