What is the Pattern here ?
Hello,
This is a piece of my Log and would like some comments of the patterns of hits it logged. I keep seeing the same Ports hit in the same order every time with a NetBIOS or other probes added in the end from time to time.
All IP's I checked so far come back to Dialup Accounts although I didn't check the 445 and ICMP hit IP's.
7/29/04 12:25:16 Rule "Block ICMP Inbound (Echo Request) " blocked (12.76.80.12,8). Details: Inbound ICMP request Local address is (-) Remote address is (12.76.80.12) Message type is "Echo Request" Process name is "N/A" 7/29/04 12:21:09 Rule "Default Block Sokets de Trois v1. Trojan" blocked (-,5000). Details: Inbound TCP connection Local address,service is (-,5000) Remote address,service is (12.76.202.102,4602) Process name is "N/A" 7/29/04 12:16:07 Rule "?Default Block MyDoom Ports 3127-3198 read more and respond »Posted 5 years ago by !:?) in Networking Firewalls