From: "Virus Guy" <
[email protected]>
|
| Approx 11:31 PM EST
|
| Unrecognized access from 38.115.4.237:4253 to TCP port 49966
|
| (some Cogentco machine - for the moment)
|
| About a dozen of these showing up in a 20 minute span (the running
| capacity of my router's log file).
|
| Each time I look, yesterday AM, PM, today, etc - there's always these
| hits to port 49966. IP's change, but within any given log view its
| always from 1 or 2 different IP's.
|
| I just started looking at the log a few days ago for another reason,
| so I don't know when these port 49966 attempts started.
|
| It's not a lot of hits (90% to 95% of hits are ports 135/139) but
| 49966 is becoming the next most common port (my ISP must already be
| blocking 445). As common as 1026 (Gnutella).
||
| The log shows only blocked attempts, so it's no problem.
|
| I'm just curious. Normally a consistent port attempt like this is
| related to a specific virus or trojan. In this case, there's no info
| at all about it.
My WallWatcher log shows ZERO WAN activity on this port see on my Linksys BEFSR81.
As you have noted, the number is low. I log 100's of thousands of port 445 and NetBIOS over
IP hits per month.