What is the Pattern here ?

Hello,

This is a piece of my Log and would like some comments of the patterns of hits it logged. I keep seeing the same Ports hit in the same order every time with a NetBIOS or other probes added in the end from time to time.

All IP's I checked so far come back to Dialup Accounts although I didn't check the 445 and ICMP hit IP's.

7/29/04 12:25:16 Rule "Block ICMP Inbound (Echo Request) " blocked (12.76.80.12,8). Details: Inbound ICMP request Local address is (-) Remote address is (12.76.80.12) Message type is "Echo Request" Process name is "N/A" 7/29/04 12:21:09 Rule "Default Block Sokets de Trois v1. Trojan" blocked (-,5000). Details: Inbound TCP connection Local address,service is (-,5000) Remote address,service is (12.76.202.102,4602) Process name is "N/A" 7/29/04 12:16:07 Rule "?Default Block MyDoom Ports 3127-3198 read more and respond »

Posted 5 years ago by !:?) in Networking Firewalls

Report misuse

Image for What is the Pattern here ?