T
tiffini
Hi,
I have noticed some interesting traffic coming from one of my pc's and then to one of my pc's.
First a little background.
I have a befsr41 router with snmp So I can log traffic going into my little network using wallwatcher and opmanager.
I have one XP machine I leave on a lot. I notice that it is sending UDP outbound from L-port 137 to R-port 137. Then in a relatively short amount of time I see an inbound request from a different IP to ports 1026 ,1027, and 1028 from a different IP that the 137 was sent from.
I have norton's running, and ad aware and spybot don't show anything.
The addresses seem to come from anywhere China, hong kong, even the US and Canada.
Any Ideas of what this is?
Log Snips:
-------------
alert_audit435.txt:20:54:06:542 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 20:54:06 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @out UDP from 10.100.1.7:137 to 221.6.163.50:137
alert_audit435.txt- alert_audit435.txt-20:54:45:033 ALERTAUDIT: System Clear: Tue Dec 26 20:54:44 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 202.97.238.132:32957 to WANIP:1026
alert_audit435.txt- alert_audit435.txt-20:55:43:724 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 20:55:43 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.159.205:19437 to WANIP:1027
alert_audit435.txt- alert_audit435.txt-20:55:43:836 ALERTAUDIT: System Clear: Tue Dec 26 20:55:43 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.159.205:19437 to WANIP:1028
alert_audit435.txt-
Log Snips:
-------------
alert_audit435.txt:22:01:00:913 ALERTAUDIT: System Clear: Tue Dec 26 22:01:00 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @out UDP from 10.100.1.7:137 to 24.64.19.74:137
alert_audit435.txt- alert_audit435.txt-22:01:42:516 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:01:42 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.191.3.147:25931 to WANIP:1026
alert_audit435.txt- alert_audit435.txt-22:02:43:193 ALERTAUDIT: System Clear: Tue Dec 26 22:02:42 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.255.139:16957 to WANIP:1027
alert_audit435.txt- alert_audit435.txt-22:02:43:213 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:02:43 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.255.139:16957 to WANIP:1028
alert_audit435.txt-
Log Snips:
-------------
alert_audit436.txt:22:36:32:840 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:36:32 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @out UDP from 10.100.1.7:137 to 204.16.209.30:137
alert_audit436.txt- alert_audit436.txt-22:38:33:569 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:38:33 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.252.244:10501 to WANIP:1026
alert_audit436.txt- alert_audit436.txt-22:38:33:686 ALERTAUDIT: System Clear: Tue Dec 26 22:38:33 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.252.244:10501 to WANIP:1027
alert_audit436.txt- alert_audit436.txt-22:38:33:694 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:38:33 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.252.244:10501 to WANIP:1027
alert_audit436.txt- alert_audit436.txt-22:38:33:697 ALERTAUDIT: System Clear: Tue Dec 26 22:38:33 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.252.244:10501 to WANIP:1028
alert_audit436.txt-
Log Snips:
-------------
alert_audit436.txt:22:45:48:878 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:45:48 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @out UDP from 10.100.1.7:137 to 24.64.5.208:137
alert_audit436.txt- alert_audit436.txt-22:51:51:654 ALERTAUDIT: System Clear: Tue Dec 26 22:51:51 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 204.16.208.76:37844 to WANIP:1026
alert_audit436.txt- alert_audit436.txt-22:51:51:661 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:51:51 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 204.16.208.76:37844 to WANIP:1026
alert_audit436.txt- alert_audit436.txt-22:51:51:769 ALERTAUDIT: System Clear: Tue Dec 26 22:51:51 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 204.16.208.76:37844 to WANIP:1027
alert_audit436.txt-
I have noticed some interesting traffic coming from one of my pc's and then to one of my pc's.
First a little background.
I have a befsr41 router with snmp So I can log traffic going into my little network using wallwatcher and opmanager.
I have one XP machine I leave on a lot. I notice that it is sending UDP outbound from L-port 137 to R-port 137. Then in a relatively short amount of time I see an inbound request from a different IP to ports 1026 ,1027, and 1028 from a different IP that the 137 was sent from.
I have norton's running, and ad aware and spybot don't show anything.
The addresses seem to come from anywhere China, hong kong, even the US and Canada.
Any Ideas of what this is?
Log Snips:
-------------
alert_audit435.txt:20:54:06:542 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 20:54:06 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @out UDP from 10.100.1.7:137 to 221.6.163.50:137
alert_audit435.txt- alert_audit435.txt-20:54:45:033 ALERTAUDIT: System Clear: Tue Dec 26 20:54:44 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 202.97.238.132:32957 to WANIP:1026
alert_audit435.txt- alert_audit435.txt-20:55:43:724 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 20:55:43 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.159.205:19437 to WANIP:1027
alert_audit435.txt- alert_audit435.txt-20:55:43:836 ALERTAUDIT: System Clear: Tue Dec 26 20:55:43 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.159.205:19437 to WANIP:1028
alert_audit435.txt-
Log Snips:
-------------
alert_audit435.txt:22:01:00:913 ALERTAUDIT: System Clear: Tue Dec 26 22:01:00 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @out UDP from 10.100.1.7:137 to 24.64.19.74:137
alert_audit435.txt- alert_audit435.txt-22:01:42:516 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:01:42 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.191.3.147:25931 to WANIP:1026
alert_audit435.txt- alert_audit435.txt-22:02:43:193 ALERTAUDIT: System Clear: Tue Dec 26 22:02:42 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.255.139:16957 to WANIP:1027
alert_audit435.txt- alert_audit435.txt-22:02:43:213 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:02:43 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.255.139:16957 to WANIP:1028
alert_audit435.txt-
Log Snips:
-------------
alert_audit436.txt:22:36:32:840 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:36:32 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @out UDP from 10.100.1.7:137 to 204.16.209.30:137
alert_audit436.txt- alert_audit436.txt-22:38:33:569 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:38:33 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.252.244:10501 to WANIP:1026
alert_audit436.txt- alert_audit436.txt-22:38:33:686 ALERTAUDIT: System Clear: Tue Dec 26 22:38:33 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.252.244:10501 to WANIP:1027
alert_audit436.txt- alert_audit436.txt-22:38:33:694 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:38:33 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.252.244:10501 to WANIP:1027
alert_audit436.txt- alert_audit436.txt-22:38:33:697 ALERTAUDIT: System Clear: Tue Dec 26 22:38:33 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 24.64.252.244:10501 to WANIP:1028
alert_audit436.txt-
Log Snips:
-------------
alert_audit436.txt:22:45:48:878 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:45:48 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @out UDP from 10.100.1.7:137 to 24.64.5.208:137
alert_audit436.txt- alert_audit436.txt-22:51:51:654 ALERTAUDIT: System Clear: Tue Dec 26 22:51:51 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 204.16.208.76:37844 to WANIP:1026
alert_audit436.txt- alert_audit436.txt-22:51:51:661 ALERTAUDIT: Update: from Clear to Clear at Tue Dec 26 22:51:51 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 204.16.208.76:37844 to WANIP:1026
alert_audit436.txt- alert_audit436.txt-22:51:51:769 ALERTAUDIT: System Clear: Tue Dec 26 22:51:51 CST 2006. Alert: 10.100.1.1_TrapsFromRouter_trap : Traffic .1.3.6.1.4.1.3955.1.1.0: @in UDP from 204.16.208.76:37844 to WANIP:1027
alert_audit436.txt-