[Oisf-users] MS Terminal Traffic on non-standard port.
David Woodfall
dave at dawoodfall.net
Mon Oct 9 23:32:19 UTC 2017
I have noticed 4 of these in my fast.log:
10/06/2017-20:43:06.327646 [**] [1:2023753:2] ET SCAN MS Terminal
Server Traffic on Non-standard Port [**] [Classification: Attempted
Information Leak] [Priority: 2] {TCP} 181.143.173.235:64705 ->
192.168.1.2:22000
All from the same IP.
I am running sshd on that port and just wondering what the chances of
someone finding that port by accident. There are no hits of him
scanning a range of ports.
I found a couple of things that run on that port, but it seems
unusual.
More information about the Oisf-users
mailing list