[Oisf-users] MS Terminal Traffic on non-standard port.

David Woodfall dave at dawoodfall.net
Mon Oct 9 23:32:19 UTC 2017


I have noticed 4 of these in my fast.log:

10/06/2017-20:43:06.327646  [**] [1:2023753:2] ET SCAN MS Terminal
Server Traffic on Non-standard Port [**] [Classification: Attempted
Information Leak] [Priority: 2] {TCP} 181.143.173.235:64705 ->
192.168.1.2:22000

All from the same IP.

I am running sshd on that port and just wondering what the chances of
someone finding that port by accident. There are no hits of him
scanning a range of ports.

I found a couple of things that run on that port, but it seems
unusual.


More information about the Oisf-users mailing list