We have received a report of suspicious network activity involving a system under your management. Details have been included at the end of this message.
Please investigate the claim and immediately let us know what you find. Be sure to include details of actions taken to prevent further abuse.
We look forward to your prompt response.
Note: If this is a critical matter or additional reports are received, we may need to immediately deactivate the system until the matter can be addressed.
-----------------------------------------------------------------------
*** If an adequate response is not received within 24 hours,
service may be suspended and a $50.00 fee will be assessed.
-----------------------------------------------------------------------
Re: [TR #2331035] 184.22.197.235 blocked at caltech.edu
184.22.197.235 was observed probing caltech.edu for security holes. It
has been blocked at our border routers. It may be compromised.
For more info contact [email protected]
Please include the entire subject line of the original message
--RuthAnne
(time zone of log is PST, which is UTC-08:00, date is MMDD)
log entries are from Cisco netflow, time is flow start time
date.time srcIP srcPort dstIP dstPort proto #pkts
1126.21:47:47.495 184.22.197.235 4310 131.215.28.54 3389 6 3
1126.22:08:08.404 184.22.197.235 4935 131.215.55.3 3389 6 1
1126.23:52:17.967 184.22.197.235 4935 131.215.252.171 3389 6 1
1127.03:16:29.590 184.22.197.235 4935 134.4.29.8 3389 6 1
1127.04:12:15.720 184.22.197.235 4935 134.4.238.6 3389 6 1
1127.04:40:06.915 184.22.197.235 4935 131.215.74.43 3389 6 1
1127.04:45:48.684 184.22.197.235 4935 131.215.24.98 3389 6 1
1127.05:10:22.583 184.22.197.235 4935 131.215.188.234 3389 6 1
1127.05:48:15.867 184.22.197.235 4935 134.4.39.87 3389 6 1
1127.05:59:40.548 184.22.197.235 4935 131.215.20.155 3389 6 1
1127.07:03:58.020 184.22.197.235 4935 131.215.69.20 3389 6 1
1127.07:10:31.159 184.22.197.235 4935 131.215.51.139 3389 6 1
1127.07:29:37.516 184.22.197.235 4935 134.4.5.179 3389 6 1
1127.08:03:03.168 184.22.197.235 4935 134.4.198.169 3389 6 1
原帖由 dotww 于 2011-11-28 07:44 发表
If an adequate response is not received within 24 hours,
service may be suspended and a $50.00 fee will be assessed.
请于24小时内回复,
否则关你服务,罚你款.