Firewall getting slammed on port 19837,help plz - testmy.net resource / tool
Home
Welcome, Guest. Please login or register.
Did you miss your activation email?

 



donations help testmy.net pay for the very high cost to run the site. Any amount is greatly appreciated.
Click to read why...

  spcr
    
News : undecided Is blue NOT your favorite color?  Well why not customize testmy.net to your liking?!  We offer over 25 theme variations, there is sure to be at least one that suits your personal style, choose one here cool October 15, 2008, 08:44:09 PM
testmy.net Broadband  |  Main Forum  |  PC Security  |  Security Threats  |  Topic: Firewall getting slammed on port 19837,help plz Advanced search
  0 Members and 1 Guest are viewing this topic. « previous next »
Pages 1 2  All Go Down
Author
Topic: Firewall getting slammed on port 19837,help plz  (Read 8938 times)
FallowEarth
Inactive Moderator
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2871



View Profile
« Reply #15 on: March 13, 2006, 12:30:39 PM »

I've ran some tests on every IP listed above, and most of the machines connected to those ips are compromised machines themselves in fact the machines above can easily be gained control of in most cases.

Probably a part of a botnet. 
Logged
Dark_Matter
Sophist Member
TMN Friend
*
Offline Offline

Posts: 489



View Profile WWW
« Reply #16 on: March 13, 2006, 01:10:52 PM »

There seems to only be a few addresses still active now of the ones listed earlier. Here is one of the few still up.

nmap -O 88.136.170.103

Starting nmap 3.81 ( http://www.insecure.org/nmap/ ) at 2006-03-13 14:05 EST
Warning:  OS detection will be MUCH less reliable because we did not find at least 1 open and 1 closed TCP port
Interesting ports on 88-136-170-103.adslgp.cegetel.net (88.136.170.103):
(The 1662 ports scanned but not shown below are in state: filtered)
PORT   STATE SERVICE
21/tcp open  ftp
Device type: general purpose|broadband router
Running: FreeBSD 4.X, Linux 1.X, OpenBSD 3.X, Zyxel ZyNOS
OS details: FreeBSD 4.10-STABLE, Linux 1.3.20 (x86), OpenBSD 3.6 x86 with pf "scrub in all", Zyxel 944S Prestige router
Uptime 3.269 days (since Fri Mar 10 07:38:25 2006)
Logged
FallowEarth
Inactive Moderator
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2871



View Profile
« Reply #17 on: March 13, 2006, 04:05:40 PM »

Try the scans found here: http://scan.sygatetech.com/ especially the UDP port scan, but also do the others.
Logged
Elite.Pete
Sophist Member
TMN Friend
*
Offline Offline

Posts: 607

Comcast 8mb/768kb


View Profile WWW
« Reply #18 on: March 13, 2006, 07:03:05 PM »

I've ran some tests on every IP listed above, and most of the machines connected to those ips are compromised machines themselves in fact the machines above can easily be gained control of in most cases.

seems like somone is running a botnet
Logged

http://www.testmy.net/o-mirror-Elite.Pete
"Vive Dieu Saint Amour"

Signature removed again due to complaints
Dark_Matter
Sophist Member
TMN Friend
*
Offline Offline

Posts: 489



View Profile WWW
« Reply #19 on: March 13, 2006, 07:16:09 PM »

I'd be intrested in getting an update on the issue, and if it's still going on. Prehaps get another list of ip's to run some more tests on. I should have actually logged into one of the machines i tested earlier to see what type of bot is being used. I would bet it's an rxbot or a variant of an rxbot.
Logged
ArcticWolf
Sr. Member
*
Offline Offline

Gender: Male
Posts: 189

Death from below


View Profile WWW
« Reply #20 on: March 13, 2006, 07:49:44 PM »

I'd be intrested in getting an update on the issue, and if it's still going on. Prehaps get another list of ip's to run some more tests on. I should have actually logged into one of the machines i tested earlier to see what type of bot is being used. I would bet it's an rxbot or a variant of an rxbot.

Nope it hasn't come back yet, which I'm happy about, but here is more of the list I copied, still have a few thousand more.... but just gave you a longer list then before that was logged yesterday.

3/12/2006 6:37:16 PM   222.47.172.201   UDP (19837)
3/12/2006 6:37:16 PM   141.149.59.22   UDP (19837)
3/12/2006 6:37:15 PM   220.234.236.153   UDP (19837)
3/12/2006 6:37:14 PM   59.115.76.111   UDP (19837)
3/12/2006 6:37:13 PM   72.60.48.108   UDP (19837)
3/12/2006 6:37:12 PM   60.48.181.32   UDP (19837)
3/12/2006 6:37:12 PM   83.112.218.130   UDP (19837)
3/12/2006 6:37:11 PM   62.43.65.188   UDP (19837)
3/12/2006 6:37:10 PM   220.131.64.127   UDP (19837)
3/12/2006 6:37:10 PM   217.132.247.241   UDP (19837)
3/12/2006 6:37:07 PM   83.228.17.4   UDP (19837)
3/12/2006 6:37:07 PM   218.106.82.166   UDP (19837)
3/12/2006 6:37:06 PM   221.10.4.37   UDP (19837)
3/12/2006 6:37:06 PM   155.92.101.45   UDP (19837)
3/12/2006 6:37:06 PM   62.14.113.99   UDP (19837)
3/12/2006 6:37:04 PM   24.84.102.76   UDP (19837)
3/12/2006 6:37:03 PM   87.248.68.1   UDP (19837)
3/12/2006 6:37:03 PM   210.85.135.29   UDP (19837)
3/12/2006 6:37:02 PM   68.155.216.130   UDP (19837)
3/12/2006 6:37:01 PM   212.108.246.254   UDP (19837)
3/12/2006 6:37:00 PM   222.35.119.52   UDP (19837)
3/12/2006 6:37:00 PM   218.172.91.169   UDP (19837)
3/12/2006 6:37:00 PM   222.156.87.148   UDP (19837)
3/12/2006 6:36:59 PM   219.68.97.151   UDP (19837)
3/12/2006 6:36:59 PM   59.115.92.127   UDP (19837)
3/12/2006 6:36:58 PM   201.10.35.97   UDP (19837)
3/12/2006 6:36:58 PM   82.39.112.157   UDP (19837)
3/12/2006 6:36:57 PM   68.84.82.88   UDP (19837)
3/12/2006 6:36:56 PM   222.37.5.185   UDP (19837)
3/12/2006 6:36:56 PM   68.187.12.220   UDP (19837)
3/12/2006 6:36:56 PM   69.112.120.89   UDP (19837)
3/12/2006 6:36:54 PM   222.78.246.25   UDP (19837)
3/12/2006 6:36:52 PM   140.114.206.1   UDP (19837)
3/12/2006 6:36:52 PM   221.201.224.58   UDP (19837)
3/12/2006 6:36:52 PM   81.197.9.123   UDP (19837)
3/12/2006 6:36:52 PM   67.171.229.139   UDP (19837)
3/12/2006 6:36:49 PM   203.188.14.75   UDP (19837)
3/12/2006 6:36:49 PM   81.170.180.6   UDP (19837)
3/12/2006 6:36:49 PM   218.17.215.13   UDP (19837)
3/12/2006 6:36:46 PM   84.59.103.120   UDP (19837)
3/12/2006 6:36:46 PM   62.168.185.229   UDP (19837)
3/12/2006 6:36:45 PM   222.222.53.22   UDP (19837)
3/12/2006 6:36:45 PM   72.19.110.180   UDP (19837)
3/12/2006 6:36:44 PM   219.79.195.97   UDP (19837)
3/12/2006 6:36:42 PM   221.0.180.30   UDP (19837)
3/12/2006 6:36:42 PM   59.147.226.63   UDP (19837)
3/12/2006 6:36:41 PM   24.87.16.129   UDP (19837)
3/12/2006 6:36:40 PM   220.135.40.232   UDP (19837)
3/12/2006 6:36:40 PM   125.24.7.117   UDP (19837)
3/12/2006 6:36:40 PM   80.195.197.45   UDP (19837)
3/12/2006 6:36:39 PM   217.75.132.147   UDP (19837)
3/12/2006 6:36:39 PM   201.8.161.203   UDP (19837)
3/12/2006 6:36:37 PM   220.165.250.4   UDP (19837)
3/12/2006 6:36:37 PM   62.57.229.248   UDP (19837)
3/12/2006 6:36:36 PM   81.35.74.217   UDP (19837)
3/12/2006 6:36:36 PM   81.229.157.93   UDP (19837)
3/12/2006 6:36:36 PM   86.132.161.64   UDP (19837)
3/12/2006 6:36:36 PM   59.147.243.80   UDP (19837)
3/12/2006 6:36:35 PM   221.234.171.239   UDP (19837)
3/12/2006 6:36:34 PM   195.74.242.222   UDP (19837)
3/12/2006 6:36:29 PM   206.248.135.159   TCP (139)
3/12/2006 6:36:29 PM   82.75.193.227   UDP (19837)
3/12/2006 6:36:27 PM   219.134.114.179   UDP (19837)
3/12/2006 6:36:27 PM   24.86.115.87   UDP (19837)
3/12/2006 6:36:26 PM   219.140.117.28   UDP (19837)
3/12/2006 6:36:26 PM   220.174.160.157   UDP (19837)
3/12/2006 6:36:25 PM   221.218.52.205   UDP (19837)
3/12/2006 6:36:24 PM   221.217.234.133   UDP (19837)
3/12/2006 6:36:24 PM   212.56.8.12   UDP (19837)
3/12/2006 6:36:23 PM   61.64.144.33   UDP (19837)
3/12/2006 6:36:21 PM   61.231.123.63   UDP (19837)
3/12/2006 6:36:20 PM   61.189.167.123   UDP (19837)
3/12/2006 6:36:19 PM   61.24.242.19   UDP (19837)
3/12/2006 6:36:19 PM   218.186.234.209   UDP (19837)
3/12/2006 6:36:17 PM   200.127.206.104   UDP (19837)
3/12/2006 6:36:17 PM   70.92.232.110   UDP (19837)
3/12/2006 6:36:16 PM   62.16.191.6   UDP (19837)
3/12/2006 6:36:15 PM   88.8.240.104   UDP (19837)
3/12/2006 6:36:15 PM   219.95.211.163   UDP (19837)
3/12/2006 6:36:15 PM   201.254.53.197   UDP (19837)
3/12/2006 6:36:13 PM   81.159.196.23   UDP (19837)
3/12/2006 6:36:13 PM   81.36.207.2   UDP (19837)
3/12/2006 6:36:12 PM   218.80.15.243   UDP (19837)
3/12/2006 6:36:12 PM   219.68.129.225   UDP (19837)
3/12/2006 6:36:11 PM   59.112.9.211   UDP (19837)
3/12/2006 6:36:10 PM   72.154.18.30   UDP (19837)
3/12/2006 6:36:07 PM   24.67.189.126   UDP (19837)
3/12/2006 6:36:07 PM   68.124.160.70   UDP (19837)
3/12/2006 6:36:05 PM   219.84.53.56   UDP (19837)
3/12/2006 6:36:04 PM   82.34.159.215   UDP (19837)
3/12/2006 6:36:03 PM   220.234.111.184   UDP (19837)
3/12/2006 6:36:03 PM   218.244.233.190   UDP (19837)
3/12/2006 6:36:00 PM   85.56.34.109   UDP (19837)
3/12/2006 6:36:00 PM   82.69.60.216   UDP (19837)
3/12/2006 6:35:59 PM   84.177.236.73   UDP (19837)
3/12/2006 6:35:59 PM   61.172.214.65   UDP (19837)
3/12/2006 6:35:59 PM   83.26.244.3   UDP (19837)
3/12/2006 6:35:58 PM   80.203.119.187   UDP (19837)
3/12/2006 6:35:57 PM   196.204.156.189   UDP (19837)
3/12/2006 6:35:56 PM   58.33.230.149   UDP (19837)
3/12/2006 6:35:55 PM   66.169.151.179   UDP (19837)
3/12/2006 6:35:54 PM   24.85.149.148   UDP (19837)
3/12/2006 6:35:54 PM   201.51.18.162   UDP (19837)
3/12/2006 6:35:54 PM   88.1.39.213   UDP (19837)
3/12/2006 6:35:53 PM   222.209.117.237   UDP (19837)
3/12/2006 6:35:53 PM   84.254.5.91   UDP (19837)
3/12/2006 6:35:52 PM   222.71.1.211   UDP (19837)
3/12/2006 6:35:52 PM   218.88.131.231   UDP (19837)
3/12/2006 6:35:52 PM   196.206.144.101   UDP (19837)
3/12/2006 6:35:51 PM   24.42.32.211   UDP (19837)
3/12/2006 6:35:50 PM   61.161.76.220   UDP (19837)
3/12/2006 6:35:49 PM   80.79.28.155   UDP (19837)
3/12/2006 6:35:49 PM   84.58.4.103   UDP (19837)
3/12/2006 6:35:49 PM   70.30.56.176   UDP (19837)
3/12/2006 6:35:47 PM   59.115.128.153   UDP (19837)
3/12/2006 6:35:46 PM   61.90.243.41   UDP (19837)
3/12/2006 6:35:46 PM   219.138.68.15   UDP (19837)
3/12/2006 6:35:45 PM   86.61.95.136   UDP (19837)
3/12/2006 6:35:44 PM   58.185.164.57   UDP (19837)
3/12/2006 6:35:42 PM   60.48.110.31   UDP (19837)
3/12/2006 6:35:42 PM   82.159.94.110   UDP (19837)
3/12/2006 6:35:40 PM   221.219.0.108   UDP (19837)
3/12/2006 6:35:39 PM   218.160.183.186   UDP (19837)
3/12/2006 6:35:38 PM   203.204.177.165   UDP (19837)
3/12/2006 6:35:37 PM   69.172.97.39   UDP (19837)
3/12/2006 6:35:37 PM   219.84.144.129   UDP (19837)
3/12/2006 6:35:36 PM   172.215.183.80   UDP (19837)
3/12/2006 6:35:35 PM   58.244.12.75   UDP (19837)
3/12/2006 6:35:35 PM   62.38.118.78   UDP (19837)
3/12/2006 6:35:31 PM   207.216.10.178   UDP (19837)
3/12/2006 6:35:31 PM   85.225.171.13   UDP (19837)
3/12/2006 6:35:30 PM   203.146.131.92   UDP (19837)
3/12/2006 6:35:28 PM   71.9.10.73   UDP (19837)
3/12/2006 6:35:26 PM   24.84.40.158   UDP (19837)
3/12/2006 6:35:25 PM   68.11.135.62   UDP (19837)
3/12/2006 6:35:24 PM   72.56.158.49   UDP (19837)
3/12/2006 6:35:24 PM   221.225.171.65   UDP (19837)
3/12/2006 6:35:24 PM   81.178.112.243   UDP (19837)
3/12/2006 6:35:21 PM   221.201.172.191   UDP (19837)
3/12/2006 6:35:20 PM   218.78.217.49   UDP (19837)
3/12/2006 6:35:17 PM   61.62.73.113   UDP (19837)
3/12/2006 6:35:17 PM   213.112.58.37   UDP (19837)
3/12/2006 6:35:17 PM   81.174.129.114   UDP (19837)
3/12/2006 6:35:17 PM   218.184.81.223   UDP (19837)
3/12/2006 6:35:16 PM   83.228.41.140   UDP (19837)
3/12/2006 6:35:16 PM   68.187.12.220   UDP (19837)
3/12/2006 6:35:15 PM   219.148.152.131   UDP (19837)
3/12/2006 6:35:15 PM   202.64.35.102   UDP (19837)
3/12/2006 6:35:14 PM   131.111.195.8   UDP (19837)
3/12/2006 6:35:12 PM   60.55.86.239   UDP (19837)
3/12/2006 6:35:10 PM   86.210.113.117   UDP (19837)
3/12/2006 6:35:10 PM   61.170.245.222   UDP (19837)
3/12/2006 6:35:09 PM   222.65.91.41   UDP (19837)
3/12/2006 6:35:08 PM   69.106.231.70   UDP (19837)
3/12/2006 6:35:07 PM   220.142.74.4   UDP (19837)
3/12/2006 6:35:06 PM   213.250.61.60   UDP (19837)
3/12/2006 6:35:03 PM   218.171.24.223   UDP (19837)
3/12/2006 6:35:03 PM   201.124.59.126   UDP (19837)
3/12/2006 6:35:01 PM   69.86.206.55   UDP (19837)
3/12/2006 6:35:01 PM   218.212.234.34   UDP (19837)
3/12/2006 6:35:01 PM   58.67.92.191   UDP (19837)
3/12/2006 6:35:00 PM   61.229.112.250   UDP (19837)
3/12/2006 6:35:00 PM   86.195.65.114   UDP (19837)
3/12/2006 6:34:59 PM   202.103.45.242   UDP (19837)
3/12/2006 6:34:57 PM   69.220.250.20   UDP (19837)
3/12/2006 6:34:55 PM   218.94.8.227   UDP (19837)
3/12/2006 6:34:55 PM   81.180.249.238   UDP (19837)
3/12/2006 6:34:53 PM   24.79.157.109   UDP (19837)
3/12/2006 6:34:52 PM   62.14.52.241   UDP (19837)
3/12/2006 6:34:51 PM   140.119.200.154   UDP (19837)
3/12/2006 6:34:51 PM   218.166.75.82   UDP (19837)
3/12/2006 6:34:51 PM   200.158.213.52   UDP (19837)
3/12/2006 6:34:49 PM   218.68.224.67   UDP (19837)
3/12/2006 6:34:48 PM   84.183.130.27   UDP (19837)
3/12/2006 6:34:47 PM   213.5.100.46   UDP (19837)
3/12/2006 6:34:45 PM   218.165.129.240   UDP (19837)
3/12/2006 6:34:45 PM   80.38.103.80   UDP (19837)
3/12/2006 6:34:45 PM   81.207.8.226   UDP (19837)
3/12/2006 6:34:42 PM   59.113.28.17   UDP (19837)
3/12/2006 6:34:41 PM   220.143.214.107   UDP (19837)
3/12/2006 6:34:41 PM   87.227.204.90   UDP (19837)
3/12/2006 6:34:38 PM   220.162.186.51   UDP (19837)
3/12/2006 6:34:37 PM   220.39.228.14   UDP (19837)
3/12/2006 6:34:37 PM   218.184.113.183   UDP (19837)
3/12/2006 6:34:36 PM   67.166.139.200   UDP (19837)
3/12/2006 6:34:35 PM   201.8.144.15   UDP (19837)
3/12/2006 6:34:35 PM   210.213.133.158   UDP (19837)
3/12/2006 6:34:34 PM   218.14.3.233   UDP (19837)
3/12/2006 6:34:34 PM   218.16.110.68   UDP (19837)
3/12/2006 6:34:33 PM   62.15.71.161   UDP (19837)
3/12/2006 6:34:33 PM   222.45.6.5   UDP (19837)
3/12/2006 6:34:32 PM   88.154.89.128   UDP (19837)
3/12/2006 6:34:31 PM   219.129.224.6   UDP (19837)
3/12/2006 6:34:30 PM   59.167.158.73   UDP (19837)
3/12/2006 6:34:28 PM   220.135.44.239   UDP (19837)
3/12/2006 6:34:27 PM   24.1.141.168   UDP (19837)
3/12/2006 6:34:27 PM   220.138.44.35   UDP (19837)
3/12/2006 6:34:26 PM   60.13.218.11   UDP (19837)
3/12/2006 6:34:26 PM   218.13.30.168   UDP (19837)
3/12/2006 6:34:26 PM   66.76.129.128   UDP (19837)
3/12/2006 6:34:25 PM   222.164.90.22   UDP (19837)
3/12/2006 6:34:25 PM   68.115.147.152   UDP (19837)
3/12/2006 6:34:25 PM   82.31.32.44   UDP (19837)
3/12/2006 6:34:24 PM   218.162.96.136   UDP (19837)
3/12/2006 6:34:24 PM   216.204.61.54   UDP (19837)
3/12/2006 6:34:24 PM   218.172.21.94   UDP (19837)
3/12/2006 6:34:23 PM   58.213.21.36   UDP (19837)
3/12/2006 6:34:23 PM   222.76.188.125   UDP (19837)
3/12/2006 6:34:22 PM   219.148.40.212   UDP (19837)
3/12/2006 6:34:22 PM   218.80.172.196   UDP (19837)
3/12/2006 6:34:21 PM   24.239.177.181   UDP (19837)
3/12/2006 6:34:21 PM   218.12.62.185   UDP (19837)
3/12/2006 6:34:21 PM   83.24.225.21   UDP (19837)
3/12/2006 6:34:20 PM   61.138.73.234   UDP (19837)
3/12/2006 6:34:20 PM   217.208.89.48   UDP (19837)
3/12/2006 6:34:20 PM   61.51.121.153   UDP (19837)
3/12/2006 6:34:19 PM   58.63.93.204   UDP (19837)
3/12/2006 6:34:19 PM   221.5.178.210   UDP (19837)
3/12/2006 6:34:18 PM   61.236.13.93   UDP (19837)
3/12/2006 6:34:15 PM   222.164.112.44   UDP (19837)
3/12/2006 6:34:15 PM   202.67.125.203   UDP (19837)
3/12/2006 6:34:13 PM   87.123.132.5   UDP (19837)
3/12/2006 6:34:11 PM   81.64.88.9   UDP (19837)
3/12/2006 6:34:11 PM   203.218.114.71   UDP (19837)
3/12/2006 6:34:09 PM   219.130.109.132   UDP (19837)
3/12/2006 6:34:06 PM   218.1.176.33   UDP (19837)
3/12/2006 6:34:06 PM   221.220.211.227   UDP (19837)
3/12/2006 6:34:03 PM   81.90.175.242   UDP (19837)
3/12/2006 6:34:02 PM   84.157.117.185   UDP (19837)
3/12/2006 6:34:02 PM   218.212.197.35   UDP (19837)
3/12/2006 6:34:02 PM   218.166.84.130   UDP (19837)
3/12/2006 6:34:02 PM   221.239.181.253   UDP (19837)
3/12/2006 6:34:02 PM   151.204.224.41   UDP (19837)
3/12/2006 6:34:00 PM   59.116.187.179   UDP (19837)
3/12/2006 6:33:59 PM   222.244.28.119   UDP (19837)
3/12/2006 6:33:58 PM   222.65.117.222   UDP (19837)
3/12/2006 6:33:58 PM   83.156.49.234   UDP (19837)
3/12/2006 6:33:58 PM   59.35.6.112   UDP (19837)
3/12/2006 6:33:57 PM   213.65.53.239   UDP (19837)
3/12/2006 6:33:57 PM   24.56.0.76   UDP (19837)
3/12/2006 6:33:57 PM   61.64.66.247   UDP (19837)
3/12/2006 6:33:55 PM   221.203.133.165   UDP (19837)
3/12/2006 6:33:54 PM   218.88.19.228   UDP (19837)
3/12/2006 6:33:54 PM   60.0.227.57   UDP (19837)
3/12/2006 6:33:54 PM   213.231.102.219   UDP (19837)
3/12/2006 6:33:53 PM   218.91.222.56   UDP (19837)
3/12/2006 6:33:52 PM   61.183.86.25   UDP (19837)
3/12/2006 6:33:51 PM   201.129.66.198   UDP (19837)
3/12/2006 6:33:50 PM   220.228.78.151   UDP (19837)
3/12/2006 6:33:50 PM   203.188.46.48   UDP (19837)
3/12/2006 6:33:49 PM   60.12.91.101   UDP (19837)
3/12/2006 6:33:48 PM   69.222.126.195   UDP (19837)
3/12/2006 6:33:48 PM   202.180.123.53   UDP (19837)
3/12/2006 6:33:48 PM   125.24.67.38   UDP (19837)
3/12/2006 6:33:47 PM   209.169.141.3   UDP (19837)
3/12/2006 6:33:44 PM   219.77.56.184   UDP (19837)
3/12/2006 6:33:44 PM   58.24.32.110   UDP (19837)
3/12/2006 6:33:41 PM   198.96.34.11   UDP (19837)
3/12/2006 6:33:40 PM   88.1.138.228   UDP (19837)
3/12/2006 6:33:37 PM   217.132.71.147   UDP (19837)
3/12/2006 6:33:36 PM   221.226.219.43   UDP (19837)
3/12/2006 6:33:34 PM   70.48.86.49   UDP (19837)
3/12/2006 6:33:34 PM   59.35.188.49   UDP (19837)
3/12/2006 6:33:33 PM   84.10.219.101   UDP (19837)
3/12/2006 6:33:32 PM   63.224.21.208   UDP (19837)
3/12/2006 6:33:31 PM   71.139.174.33   UDP (19837)
3/12/2006 6:33:31 PM   72.240.254.226   UDP (19837)
3/12/2006 6:33:31 PM   65.78.11.62   UDP (19837)
3/12/2006 6:33:31 PM   218.22.192.2   UDP (19837)
3/12/2006 6:33:30 PM   84.66.166.188   UDP (19837)
3/12/2006 6:33:27 PM   222.5.164.92   UDP (19837)
3/12/2006 6:33:27 PM   220.112.36.207   UDP (19837)
3/12/2006 6:33:26 PM   194.54.145.167   UDP (19837)
3/12/2006 6:33:25 PM   213.180.60.174   UDP (19837)
3/12/2006 6:33:25 PM   85.220.67.140   UDP (19837)
3/12/2006 6:33:24 PM   71.125.41.158   UDP (19837)
3/12/2006 6:33:23 PM   62.0.175.176   UDP (19837)
3/12/2006 6:33:23 PM   140.116.141.200   UDP (19837)
3/12/2006 6:33:23 PM   196.217.107.130   UDP (19837)
3/12/2006 6:33:23 PM   68.205.97.30   UDP (19837)
3/12/2006 6:33:21 PM   69.73.211.138   UDP (19837)
3/12/2006 6:33:17 PM   61.185.60.138   UDP (19837)
3/12/2006 6:33:17 PM   86.201.13.61   UDP (19837)
3/12/2006 6:33:16 PM   222.50.244.23   UDP (19837)
3/12/2006 6:33:12 PM   125.213.36.102   UDP (19837)
3/12/2006 6:33:10 PM   59.112.196.88   UDP (19837)
3/12/2006 6:33:09 PM   218.165.72.49   UDP (19837)
3/12/2006 6:33:08 PM   80.56.224.246   UDP (19837)
3/12/2006 6:33:08 PM   218.168.12.206   UDP (19837)
3/12/2006 6:33:07 PM   220.135.210.166   UDP (19837)
3/12/2006 6:33:07 PM   203.122.106.22   UDP (19837)
3/12/2006 6:33:07 PM   80.57.56.107   UDP (19837)
3/12/2006 6:33:05 PM   72.155.156.108   UDP (19837)
3/12/2006 6:33:04 PM   83.5.67.186   UDP (19837)
3/12/2006 6:33:03 PM   218.136.232.22   UDP (19837)
3/12/2006 6:33:03 PM   142.204.8.55   UDP (19837)
3/12/2006 6:33:03 PM   218.163.100.217   UDP (19837)
3/12/2006 6:33:01 PM   220.135.16.166   UDP (19837)
3/12/2006 6:33:01 PM   58.8.111.28   UDP (19837)
3/12/2006 6:33:01 PM   84.56.254.193   UDP (19837)
3/12/2006 6:33:01 PM   222.222.42.243   UDP (19837)
3/12/2006 6:32:58 PM   213.98.193.6   UDP (19837)
3/12/2006 6:32:58 PM   218.160.29.207   UDP (19837)
3/12/2006 6:32:57 PM   70.30.111.138   UDP (19837)
3/12/2006 6:32:57 PM   61.149.6.39   UDP (19837)
3/12/2006 6:32:54 PM   61.49.145.136   UDP (19837)
3/12/2006 6:32:52 PM   85.136.69.60   UDP (19837)
3/12/2006 6:32:52 PM   194.126.113.98   UDP (19837)
3/12/2006 6:32:51 PM   218.102.170.192   UDP (19837)
3/12/2006 6:32:50 PM   218.172.163.116   UDP (19837)
3/12/2006 6:32:49 PM   210.58.150.49   UDP (19837)
3/12/2006 6:32:49 PM   201.255.192.234   UDP (19837)
3/12/2006 6:32:49 PM   218.168.135.9   UDP (19837)
3/12/2006 6:32:48 PM   88.7.110.147   UDP (19837)
3/12/2006 6:32:47 PM   66.213.200.122   UDP (19837)
3/12/2006 6:32:46 PM   65.93.2.73   UDP (19837)
3/12/2006 6:32:44 PM   72.79.29.64   UDP (19837)
3/12/2006 6:32:43 PM   219.137.67.226   UDP (19837)
3/12/2006 6:32:43 PM   84.242.180.34   UDP (19837)
3/12/2006 6:32:43 PM   24.126.89.109   UDP (19837)
3/12/2006 6:32:42 PM   68.146.107.123   UDP (19837)
3/12/2006 6:32:42 PM   60.50.201.209   UDP (19837)
3/12/2006 6:32:42 PM   60.240.3.176   UDP (19837)
Logged

Dark_Matter
Sophist Member
TMN Friend
*
Offline Offline

Posts: 489



View Profile WWW
« Reply #21 on: March 13, 2006, 08:05:53 PM »

Major botnet here, and it appears i was right with my rxbot assumption. It also appears they are trying to add your machine, or were trying to add your machine to their collection. Typically they scan many ip ranges looking for machines with certain exploits actually really basic exploits then infected them. If they have a good working lsass they can have great success in infecting many thousands of machines. A machine kept up on security updates, and with good antivirus is usually pretty safe, but i'd still look for running processes like rxbots.exe, or any unfamiliar processes altogether. If i can guess or figure out the password to gain control over them i could infact disassemble the whole botnet.  ;)
Logged
ArcticWolf
Sr. Member
*
Offline Offline

Gender: Male
Posts: 189

Death from below


View Profile WWW
« Reply #22 on: March 13, 2006, 08:24:14 PM »

Well like I said it was bouncing off my firewall,no packets were ever sent out, plus I did a complete test at ShieldsUP website, and every test and port came out stealthed.
Logged

tommie gorman
Sophist Member
TMN Seasoned Veteran
*
Offline Offline

Gender: Male
Posts: 9988


"OLD GLORY"


View Profile
« Reply #23 on: March 14, 2006, 12:05:53 AM »

Unfortunetly sometimes after having had a trojan, or having been hacked the only sure way to know your system is truly clean is a fresh install. I'm not saying this is what you should do. It's obvious your situation should be examined more closely before any drastic action is taken.
Depends on what is on comp. Mine took 4 1/2 hours last time for fresh install and back on to the forum.
Logged

IF YOU DON'T STAND BEHIND OUR TROOPS, PLEASE, FEEL FREE TO STAND IN FRONT OF THEM !!!

"an old country hick from america"

Sprint EVDO Rev. A * AMD 64 3500+ 2.2 GHz cpu Ram 2GB/XP Home * TCP Optimizer
FallowEarth
Inactive Moderator
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2871



View Profile
« Reply #24 on: March 14, 2006, 01:41:06 AM »

3/12/2006 6:37:12 PM   60.48.181.32   UDP (19837)

look 60.48.181.32 ... found
Name    : tm.net.my                  (.MY  | Malaysia)
Address : 60.48.181.32

LOL....I thought the name of this compromised machine was kind of ironic.
Logged
FallowEarth
Inactive Moderator
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2871



View Profile
« Reply #25 on: March 14, 2006, 02:01:06 AM »

I hope thats not the case I'm having similar attacks as well. (Port 32459)

I believe Port 32459 is the default port for uTorrent...

Exactly.  I stopped using uTorrent when I discovered so many blocked access attempts targetting this port.  They were sourced from all over the world (usually Asia-Pacific, but some from Europe and N. America too) using many different ports.

Logged
ArcticWolf
Sr. Member
*
Offline Offline

Gender: Male
Posts: 189

Death from below


View Profile WWW
« Reply #26 on: March 14, 2006, 02:22:13 AM »

Exactly.  I stopped using uTorrent when I discovered so many blocked access attempts targetting this port.  They were sourced from all over the world (usually Asia-Pacific, but some from Europe and N. America too) using many different ports.



Yes I get hit on that port also when using uTorrent, but is there any other torrent program that doesn't do that? I don't believe there is... and that is the price you pay for using them.
Logged

FallowEarth
Inactive Moderator
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2871



View Profile
« Reply #27 on: March 14, 2006, 03:01:21 AM »

Yes I get hit on that port also when using uTorrent, but is there any other torrent program that doesn't do that? I don't believe there is... and that is the price you pay for using them.

I uninstalled it.  I would prefer not using that method of file transfer. 
Logged
Print  Pages 1 2  All Go Up
testmy.net Broadband  |  Main Forum  |  PC Security  |  Security Threats  |  Topic: Firewall getting slammed on port 19837,help plz « previous next »
Jump to:  

    
testmy.net's forum is proudly Powered by SMF | SMF © 2006-2007, Simple Machines LLC
Bookmark: Del.icio.us    StumbleUpon
 
 

 

© 1999-2008 testmy.net - Contact - Legal - Facts & FAQs
Page Loading Stats: This forum Page created in 0.158 seconds with 49 queries.