More slow SNMP scans

From: Jim Watt (wattjgat_private)
Date: Fri Feb 22 2002 - 18:35:38 PST

  • Next message: Jason Dixon: "Checking for rootkits"

    Today (22 February 2002) we observed the following SNMP traffic:
    
    Feb 22 16:03:34 denied udp 194.230.130.206(10000) -> 192.52.153.5(161)
    Feb 22 16:12:15 denied udp 194.230.130.206(10000) -> 192.52.153.16(161)
    Feb 22 16:30:24 denied udp 194.230.130.206(10000) -> 192.52.153.39(161)
    Feb 22 16:39:04 denied udp 194.230.130.206(10000) -> 192.52.153.50(161)
    
    Two days before this incident, the following traffic was logged:
    
    Feb 20 16:03:35 denied udp 194.230.140.47(10000) -> 192.52.153.5(161)
    Feb 20 16:12:17 denied udp 194.230.140.47(10000) -> 192.52.153.16(161)
    
    Times are PST, and are accurate.
    
    The "abuse" contact for the net involved has been notified.
    
    Jim
    --
    Jim Watt                               wattjgat_private
    Applied Biosystems                     Voice (desk): +1 408 577 2228
    3833 North First Street                Fax:          +1 408 894 9307
    San Jose CA 95134-1701                 Voice (main): +1 408 577 2200
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Sun Feb 24 2002 - 21:14:49 PST