Recently Viewed: Home > WhoIs > TraceRoute > Timeline > Investigations
Investigations
Summary Data
Source IP addresses
SrcIPs - Very Noisy guys - NOTES
SrcIPs2 - 24 to 6-packets activity
SrcIPs3 - 6, 5, 4, 3-packets activity - Mainly other worms, but take a look
SrcIPs4 - All 3-packets activity - Blaster among those - NOTES
SrcIPs5 - All 3-packets activity - Blaster among those
SrcIPs6 - 3 and 2-packets activity
SrcIPs7 - 2 and 1-packet activity
SrcIPs8 - All 1-packet activity
SrcIPs9 - All 1-packet activity
SrcIPs10 - All 1-packet activity - NOTES
 
20382 total
 
369 total
 
106 total





Port Scans
Dani@NL: Port scans moved to Question4 that is where they belong. I am starting to sort out this huge 'investigations' zone and populating the right answers - otherwise we don't get the status (at least I don't) of how we are running the challenge - Actually some probes are not really 'scans' but 'recoignassance activity' - in this case they might be more appropriate in Question3

Source And Dest. Ports
Dani@NL: I moved the PORTS pages to Top7Ports for it is far more reachable from most of the first questions, and it can help navigate through the wiki.
Anyway, for further searching, this is the list of the first (simply alphabetical/numerical order - the high-ports are most likely return ports anyway) DST ports:
2, 5, 18, 21, 22, 23, 25, 53, 57, 79, 80, 81, 82, 88, 110, 111, 113, 135, 139, 225, 389, 443, 445, 455, 554, 587, 901


IP Addresses

Honey Pots:
Honeypots addresses moved to LayoutHoney which in turns is linked from Question9 - it is where it is requested, I am starting to sort out this huge 'investigations' zone and populating the right answers - otherwise we don't get the status (at least I don't) of how we are running the challenge - Dani3l3


DNS Servers:
22.22.22.40
23.23.23.60

Local:
127.0.0.1

External Addresses:
66.186.83.178 - This is the source of the spike on Feb3 - port 445 and 139
66.60.166.84 - This is another source of a spike.
67.123.234.132 - Another spike.
208.61.160.83 - another spike
83.30.20.8 - another spike
Microsoft - Addresses of Microsoft.
69.133.57.67 - (US) - Four packets to DstPort2 and that's it!
81.248.48.49
80.116.93.36 (Italy) - Searching for FTP servers - maybe an autorooter ?
203.200.213.182 (India) - A tale
200.151.230.146
62.126.79.x (United Kingdom) 23 Addresses in UK doing weird stuff - The Mark of the Illuminati
217.219.118.194 - 5 packets to port 5 from Iran
212.120.160.229 (Russia) - What is interesting in DstPort57 ?
218.64.117.195 (China) - Spotted in typical port scanning activity
81.196.129.x
220.170.88.7 - Searching for open proxies

CountryData
Iran
Israel
Italy
Romania