RE: Port 445 increase?

From: Jim Harrison (SPG) (jmharrat_private)
Date: Mon Jun 03 2002 - 22:32:30 PDT

  • Next message: Pieter-Bas IJdens: "Re: scanning from WANADOO-CABLE-BD"

    Yes; my ISA servers have logged these scans and continued on their merry way.
    I have to be careful; having ISA servers between me and them can make me awfully lazy in my log scan habits...  ;-)
     
    Jim
    
    	-----Original Message----- 
    	From: Mike Hrubes [mailto:MHrubesat_private] 
    	Sent: Mon 6/3/2002 14:02 
    	To: incidentsat_private 
    	Cc: 
    	Subject: Port 445 increase?
    	
    	
    
    	Since around noon today (CST), we've really been getting hammered with tcp 445.  Interestingly, it appears to be a tool or worm doing the scanning.  All requests seem to follow the same basic format of ICMP, then 445, followed by nbname.  The requests are coming from many many different IPs, but are all directed at a single box on our network.
    	
    	Just curious if anyone else out there is seeing anything like this?
    	
    	Thanks!
    	
    	MH
    	
    	----------------------------------------------------------------------------
    	This list is provided by the SecurityFocus ARIS analyzer service.
    	For more information on this free incident handling, management
    	and tracking system please see: http://aris.securityfocus.com
    
    	
    	
    
    



    This archive was generated by hypermail 2b30 : Tue Jun 04 2002 - 08:29:30 PDT