Firewall Alert
178.33.224.175 - Continuous ICMP ping id-0 to all our public facing IP Addresses
[00001] 2012-05-14 18:09:02 [Root]system-critical-00441: ICMP ping id=0! From 178.33.224.175 to 66.20.195.70, proto 1 (zone Untrust, int ethernet0/2). Occurred 1 times.
[00002] 2012-05-14 18:08:34 [Ro...
60.217.235.5 - Repeats attempt to log into firewall
Repeats attempt to log into firewall. Firewall sees numerous attempts to log in from this location. This is not coming from a welcommed user....
108.170.22.186 - HackAttack: [SPI:Illegal connection state attack] + INFO
May 16 13:58:29 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.170.22.186 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/108.170.22.186 RESULT:
108.170.22.186 IP ...
95.211.153.68 - HackAttack: [SPI:Illegal connection state attack]
May 9 08:38:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 95.211.153.68 to 80.220.22.74
May 16 08:29:00 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
76.93.105.16 - HackAttack: [SPI:Illegal connection state attack]
May 16 07:24:01 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 76.93.105.16 to 80.220.22.74
May 16 07:24:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
222.165.47.82 - HackAttack: [SPI:Illegal connection state attack]
May 16 00:46:08 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 222.165.47.82 to 80.220.22.74
May 16 00:46:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
188.130.251.77 - ÐопÑÑки вÑода в ÑиÑÑÐµÐ¼Ñ Ð¿Ð¾ VNC
ÐеÑколÑко дней ÑегÑл&...
58.218.199.250 - Detect Port Scanning attack
Had 1 attack today 16. 05.2012
Had 1 attack today 16. 05.2012 Had 1 attack today 16. 05.2012 Had 1 attack today 16. 05.2012 Had 1 attack today 16. 05.2012 ...
188.127.236.164 - Continual port scanning at intervals of 3-10 minutes
[INFO] Tue May 15 00:50:31 2012 Blocked incoming TCP packet from 188.127.236.164:2106 to 109.173.114.61:50803 as SYN:ACK received but there is no active connection
[INFO] Tue May 15 00:47:15 2012 Bloc...
85.17.31.78 - HackAttack: [SPI:Illegal connection state attack]
May 15 08:47:39 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 85.17.31.78 to 80.220.22.74
May 15 09:53:52 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
178.33.224.175 - HackAttack: [SPI:Illegal connection state attack]
May 15 00:09:21 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 178.33.224.175 to 80.220.22.74
May 15 00:24:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
64.188.63.33 - HackAttack: [SPI:Illegal connection state attack]
May 14 23:32:55 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 64.188.63.33 to 80.220.22.74
May 14 23:33:17 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
184.173.245.180 - HackAttack: [SPI:Illegal connection state attack] + INFO
May 14 13:29:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 184.173.245.180 to 80.220.22.74
May 14 16:43:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
118.249.45.211 - Gmail Alert, Unauthorized to access my email
Aloha,
I would lile to report the IP Address 118.249.45.211 for trying to access my personal email. I received an account alert from gmail, that someone with that IP address in China is trying to ac...
178.33.224.175 - HackAttack: [SPI:Illegal connection state attack]
May 14 08:08:40 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 178.33.224.175 to 80.220.22.74
May 14 08:28:02 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
218.93.205.110 - Being picked up by Malware bytes and blocked on outbound
Being picked up by malware bytes and blocked for outbound -- unable to find infection. Malware bytes is unable to find any problem -- Symantec anti-virus unable to find problem...
2.40.206.255 - Port Scan
FIREWALL replay check (1 of 1): Protocol: ICMP Src ip: 2.40.206.255 Dst ip: 00.000.000.73 Type: Destination Unreachable Code: Port Unreacheable
FIREWALL replay check (1 of 10): Protocol: ICMP Src ip:...
70.31.58.2 - HackAttack: [SPI:Illegal connection state attack]
May 13 12:21:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 70.31.58.2 to 80.220.22.74
May 13 12:21:48 HackAttack: [SPI:Illegal connection state attack] ICMP packer from...
184.82.176.162 - HackAttack: [SPI:Illegal connection state attack]
May 10 22:57:55 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 184.82.176.162 to 80.220.22.74
May 12 21:20:50 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
68.67.159.206 - Risky Connection blocked by McAfee
Just a little freaky to see that this \"Risky Connection Blocked\" by McAfee. Maybe the future will be the demise of the computer and people will get back to living life in \"Real Time...
91.196.216.64 - 91.196.216.64 Sudden Pop Up on AV
Tasks: Playing WoW & Listening to \"Dream On - Aerosmith\" on YouTube (video which itself acts odd itself in comparison to all the other videos. Absolutly no other site or program opened...
147.52.41.82 - Tried to hack my network through my firewall.
The person behind this IP address tried to log into my firewall, but he got locked after three failed attempts. The attempted attacks took place at 11:04 AM EET....
59.127.129.167 - tried to hack my network through my firewall
The person behind this IP address attempted to log in my firewall.But after three failures he was locked.this is an unethical practice by a reknowed company.STOP IT....
24.203.51.207 - HackAttack: [SPI:Illegal connection state attack]
May 9 13:25:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.203.51.207 to 80.220.22.74
May 9 13:25:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
217.199.231.221 - HackAttack: [SPI:Illegal connection state attack]
May 9 03:26:58 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 217.199.231.221 to 80.220.22.74
May 9 03:26:58 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
123.203.211.53 - Scan ports
[INFO] Wed May 09 02:03:24 2012 Blocked incoming TCP connection request from 123.203.211.53:50270 to 109.173.114.61:13500
[INFO] Wed May 09 02:03:21 2012 Blocked incoming TCP connection request from 1...
188.122.91.29 - HackAttack: [SPI:Illegal connection state attack]
May 7 23:05:01 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 188.122.91.29 to 80.220.22.74
May 8 01:21:40 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
50.97.43.162 - HackAttack: [SPI:Illegal connection state attack] + INFO
May 7 20:45:43 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.97.43.162 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/50.97.43.162 RESULT:
50.97.43.162 IP addre...
188.122.95.81 - HackAttack: [SPI:Illegal connection state attack]
Mar 6 08:07:26 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 188.122.95.81 to 80.220.22.74
May 7 16:18:34 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
178.204.108.63 - HackAttack: [SPI:Illegal connection state attack]
May 6 19:51:49 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 178.204.108.63 to 80.220.22.74
May 6 19:51:49 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
May 6 10:02:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
May 7 08:06:33 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
174.138.169.90 - HackAttack: [SPI:Illegal connection state attack]
Apr 6 06:20:43 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.138.169.90 to 80.220.22.74
May 7 01:20:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
41.105.113.220 - HackAttack: [SPI:Illegal connection state attack]
May 6 17:13:21 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 41.105.113.220 to 80.220.22.74
May 6 17:13:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
99.250.64.62 - HackAttack: [SPI:Illegal connection state attack]
May 6 15:06:52 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 99.250.64.62 to 80.220.22.74
May 6 15:06:52 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
98.227.19.60 - HackAttack: [SPI:Illegal connection state attack]
May 6 15:05:00 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 98.227.19.60 to 80.220.22.74
May 6 15:05:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
74.63.242.243 - HackAttack: [SPI:Illegal connection state attack]
May 6 13:29:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 74.63.242.243 to 80.220.22.74
May 6 15:25:41 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
222.184.232.2 - Port Scan
Every hour my firewall is warn me about this ip. Tells me it scan my ports. I hope my firewall is good enough to defend this jerk....
99.250.64.62 - HackAttack: [SPI:Illegal connection state attack]
May 6 03:39:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 99.250.64.62 to 80.220.22.74
May 6 03:39:16 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
88.198.148.208 - HackAttack: [SPI:Illegal connection state attack]
May 6 02:03:39 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 88.198.148.208 to 80.220.22.74
May 6 11:25:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
99.250.64.62 - HackAttack: [SPI:Illegal connection state attack]
Feb 7 10:08:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 99.250.64.62 to 80.220.22.74
May 5 21:56:16 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
188.122.91.29 - HackAttack: [SPI:Illegal connection state attack]
May 5 19:20:48 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 188.122.91.29 to 80.220.22.74
May 5 19:44:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
98.227.19.60 - HackAttack: [SPI:Illegal connection state attack]
May 5 10:05:41 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 98.227.19.60 to 80.220.22.74
May 5 10:05:41 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
98.227.19.60 - HackAttack: [SPI:Illegal connection state attack]
May 5 04:02:35 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 98.227.19.60 to 80.220.22.74
May 5 04:02:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
193.164.132.11 - HackAttack: [SPI:Illegal connection state attack]
May 4 22:46:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 193.164.132.11 to 80.220.22.74
May 4 23:48:33 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
91.217.178.18 - 91.217.178.18
Hubo un intento de conexión riesgoso a mi PC desde esta dirección IP, que fue detectado por McAfee Internet Security y este intento fue bloqueado por McAfee....
37.59.17.26 - HackAttack: [SPI:Illegal connection state attack]
May 4 02:52:17 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 37.59.17.26 to 80.220.22.74
May 4 02:52:19 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
50.97.32.38 - HackAttack: [SPI:Illegal connection state attack] + INFO
May 3 19:27:40 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.97.32.38 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/50.97.32.38 RESULT:
50.97.32.38 IP address ...
87.248.122.122 - Hacking
I get from eset smart security the a message about the firewall that says: detected covert channel exploit in icmp packet from ip 87.248.122.122...
66.150.14.86 - Intrusion Attempts from 66.150.14.86
Two intrusion attempts from 66.150.14.86 into Chrome, both blocked by firewall, one at 2/26/2012 6:59:53 PM PST and another at 2/26/2012 7:00:04 PM PST. The intrusion attempts come from users of Inte...
37.9.61.169 - Intrusion Attempt by 37.9.61.169
Intrusion attempts into Chrome by 37.9.61.169 from Switzerland and Belgium. They Suck. Attempts failed. Put The Hurt On \'Em. Here are some details regarding this loser.
inetnum: 37.9.61.0 - 3...
81.17.26.199 - Intrusion Attempt from 81.17.26.199
It Came from Russian Federation from 81.17.26.199, attempted to intrude into Internet Explorer, failed. They Suck. This is my complaint about them. Put The Hurt On \'Em....
212.117.183.19 - mailware
its fukn annoying its fukn annoyingits fukn annoyingits fukn annoyingits fukn annoyingits fukn annoyingits fukn annoyingits fukn annoyingits fukn annoyingits fukn annoyingits fukn annoyingits fukn ann...
146.185.218.147 - Blackhole Toolkit Attack
Symantec Endpoint Protection Report (2012.05.03 19:38:05) :
[SID: 25267] Web Attack: Blackhole Toolkit Website 14 attack blocked. Traffic has been blocked for this application: \\DEVICE\\HARDDISKVOLU...
190.2.39.193 - Illegal login
Get a message from my system about illegal requests to my network. That ip tries an illegal login into my system. I\'ve blocked it. Hope that entry is helpful....
109.163.230.114 - Malwarebytes
Every five of 1o minutes Malwarebytes aware IP-BLOCK 109.163.230.114 (Type: outgoing). What is this? Kind of very annoying! Juts to complete 25 words required! A bit annoying too!...
58.218.199.227 - Port scanning
Repeated port scanning from IP 58.218.199.227
Repeated port scanning from IP 58.218.199.227
Repeated port scanning from IP 58.218.199.227
Repeated port scanning from IP 58.218.199.227
Repeated port sc...
66.96.130.235 - Firewall Alert
Site has hit several users through firewall (5000+ average hits). Have blocked them from the firewall in an effort to reduce unwanted hits. This needs to stop....
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Apr 30 04:25:28 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
May 2 23:56:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
37.59.88.148 - HackAttack: [SPI:Illegal connection state attack]
May 2 16:21:14 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 37.59.88.148 to 80.220.22.74
May 2 16:51:08 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
37.59.88.148 - HackAttack: [SPI:Illegal connection state attack]
Apr 26 16:42:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 37.59.88.148 to 80.220.22.74
May 2 08:59:33 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
222.186.26.29 - 222.186.26.29
This IP address tried to connect to some unknown web site... Not the first time to do this... Some help will be great. Tnx in advance....
254.1.168.192 - Hacker
This hacker has been trying to get into my computer for months. Sometime two in a minute. Nobody seems to know what to do and I was advised to come to this site.
Thank you...
76.100.224.104 - HackAttack: [SPI:Illegal connection state attack]
May 1 21:22:56 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 76.100.224.104 to 80.220.22.74
May 1 21:23:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
58.218.199.227 - Port Scanning
Repeated Port Scanning from IP 58.218.149.217
Repeated Port Scanning from IP 58.218.199.147
Repeated Port Scanning from IP 58.218.199.250
Repeated Port Scanning from IP 58.218.199.227
Port Scanning-P...
74.125.79.132 - ....
My firewall has shown two times already that they\'re trying to web attack my computer. Norton Antivirus tells me the same. The last attack was today, on the first May 3:49 AM in Eastern European time...
213.115.122.97 - HackAttack: [SPI:Illegal connection state attack]
Apr 30 23:36:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 213.115.122.97 to 80.220.22.74
Apr 30 23:36:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
182.71.36.9 - Too many attempts
Firewall Alert : There will too many attempts from this IP address 182.71.36.9 and it seems trying to login to our firewall.
Please take action as soon as possible.
Regards,
NCH...
221.1.98.154 - HackAttack: [SPI:Illegal connection state attack]
Apr 29 16:58:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 221.1.98.154 to 80.220.22.74
Apr 29 16:58:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Apr 17 11:59:54 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Apr 29 10:56:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
95.211.153.68 - HackAttack: [SPI:Illegal connection state attack]
Apr 27 04:02:58 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 95.211.153.68 to 80.220.22.74
Apr 28 18:12:14 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
63.223.107.250 - web attack: malicious website accessed 2
An intrusion attempt by acfchadci.co.cc was blocked by my Norton anti virus.
This is the another day attack to my computer. What should I do to stop them....
206.161.121.4 - SVCHOST.Exe Trojan
the svchost.exe trojan i have recently acquired, just so happen to be trying to send things to this IP address. Worst part about it is that once you delete the svchost it comes right back on reboot...
91.226.212.41 - intrusive ip
Same, my firewall send me five alert for this IP adress on two days please put this adress in you database thank you very much !...
108.170.33.10 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 27 03:22:46 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.170.33.10 to 80.220.22.74
Apr 27 03:25:32 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
65.55.17.39 - netstat -b
to that ip, is sending information from my computer.
the name of the process that sends information is, \"sidebar.exe\". MICROSOFT Company. IS REMOTE NETSTAT -b. ...
37.59.88.148 - HackAttack: [SPI:Illegal connection state attack]
Apr 26 01:43:32 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 37.59.88.148 to 80.220.22.74
Apr 26 13:30:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
31.3.225.166 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 24 22:41:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 31.3.225.166 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/31.3.225.166 RESULT:
31.3.225.166 IP addres...
37.59.88.148 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 25 21:14:32 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 37.59.88.148 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/37.59.88.148 RESULT:
37.59.88.148 IP addres...
173.194.35.49 - detect nod32
I HAVE A PC IN DURING OF TIME WHEN I CONNECT TO WEB EVERY DAY MY ANTI VIRUS (NOD32) ALARM ME THAT THIS IP IS TRY TO PORT SCANNING YOUR COMPUTER WHITH ABOVE IP.
THANKS...
184.72.205.105 - Trying to access backend of site
I am constantly getting a warning (2000) emails from my RS Firewall for my website that this ip is trying to get into the Backend of my website....
217.164.228.142 - 217.164.228.142,217.110.97.194,
keep having random port scans and Dos attacks RST and ACK along remote access attempts. These guys are attacking ports 80,:49955 headbanging....
50.115.122.68 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 24 00:50:38 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.115.122.68 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/50.115.122.68 RESULT:
50.115.122.68 IP ad...
41.218.249.119 - port scan detected
this is the 10 attempt all begining with 41. its happening every 30 min. the first 9 were from south africa. this one is from ghana. why is this happening?...
41.242.209.38 - 9th attempt on my computer
this is the 9th attempt from south africa in the last 3 hrs. they use a diffrent ip address each time. all can be traced back to south africa. thank you....
94.245.121.253 - Iphlpsvc.dll Svchost
Bueno al parecer es una nueva forma de entrar en el pc, a traves del servicio de teredo svchost intenta conectarse a este servidor en UK que pertenece a Microsoft. Cuando esta alerta salta hay que det...
206.253.168.252 - Looking for openings
That IP 206.253.168.252
Persistently scans the ports.
Every ten or fifteen minutes.
And so it is more than a month.
It would be too much. Admonish the guy. Thanks...
70.38.12.164 - Attack on Joomla
This address has attempted to access our Joomla administration area on April 9th, 2012. it attempted to log in over 1200 times during a 25 minute period....
83.42.224.55 - Attack on Joomla
Tried to log into the Joomla admin area of our site. We have RSFirewall installed and it reported this to us four times within one minute....
67.219.36.200 - HackAttack: [SPI:Illegal connection state attack]
Apr 22 19:19:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 67.219.36.200 to 80.220.22.74
Apr 22 19:37:56 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
78.106.174.133 - DENIAL OF SERVICE
MY FIREWALL REPORTS A JOLT2 ATTACK.
JOLT2 ATTACK CONSISTING IN FLOODING ILLEGALLY FRAGMENT ICMP OR UDP PACKETS INTO MY COMPUTER. THIS CAUSES MY CPU UTILIZATION TO BE 100%...
89.28.87.114 - unotherized access
Logon Failure:
Reason: Unknown user name or bad password
User Name: gsdfgsdf
Domain:
Logon Type: 3
Logon Process: Advapi
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
...
[INFO] Sun Apr 22 19:27:47 2012 Blocked incoming TCP packet from 154.35.164.12:80 to 109.173.114.61:6119 as SYN:ACK received but there is no active connection
[INFO] Sun Apr 22 19:27:04 2012 Blocked i...
58.218.199.227 - TCP Flood
TCP flood From 58.218.199.227 port:12200 To 188.222.225.115 port:808
Found this on my route firewall log, don\'t really understand it but I can guess it\'s not a good thing....
31.204.153.241 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 22 07:31:48 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 31.204.153.241 to 80.220.22.74
Apr 22 07:31:58 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
58.218.199.147 - my computer block an atack from 58.218.199.147
my computer block an attack from 58.218.199.147
any advice ??? I don\'t know what to do or why this is happening..
do you have any thing to help block these attacks
...
146.0.74.28 - Trying to access Joomla site
I am being notified of unauthoized access attempt to administrator end of Joomla site. Blocked by RSFirewall. Attempt every 5 minutes or less. Have been continuing for 24 hours....
37.59.198.54 - Numerous attempts from this site to install a Hack Tool Kit
SEP IDS Alerted numerous times when user was at this site, attempts to install a root kit - site does not appear to be legit and needs to be blacklisted...
94.245.121.253 - 94.245.121.253
Noticed there is no complain option named M-I-5
Computer froze, after hard reboot anti-virus/firewall was deactivated. And could not be ran, did a quick re-install of firewall and immediately 94.245....
195.97.97.219 - subject is trying to get unauthorized access
The PC with address 195.97.97.219 is constantly trying to access our network. Not only to our own network but also to 2 other affiliate of ours.
...
66.196.59.189 - HackAttack: [SPI:Illegal connection state attack]
Apr 19 12:15:33 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 66.196.59.189 to 80.220.22.74
Apr 19 12:15:36 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
58.218.199.87 - Random port requests
We are getting constant alerts from our firewall that this address is trying to connect. It seems to be using lots of random ports....
204.47.73.100 - spoof attack
ISA Server detected a spoof attack from Internet Protocol (IP) address 204.47.73.100. A spoof attack occurs when an IP address that is not reachable via the interface on which the packet was received....
87.112.117.222 - half-scan attack
ISA Server detected an Internet Protocol (IP) half-scan attack from IP address
ISA Server detected an Internet Protocol (IP) half-scan attack from IP address...
67.212.93.131 - HackAttack: [SPI:Illegal connection state attack]
Apr 17 15:29:34 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 67.212.93.131 to 80.220.22.74
Apr 17 15:43:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Apr 16 05:04:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Apr 17 01:53:28 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
184.173.195.45 - caught in the firewall logs
yeah ive got broken connection attempts in my firewall from last night without even having a pc on.... theyve been trying to login to my router for the past week and now im reporting it. i had a lady ...
184.173.195.64 - ip found in firewall
yes got an alert in my firewall from this ip as a dropped packed. i didnt have a computer on and theyre still trying to tear down the firewall.... little does he know im logging it and fixing to repor...
89.149.242.175 - Constantly attacking my Firewall from 89.149.242.175
Has been probing all my ports in my firewall whole day, and apparently is trying to get into my computer using some sort of port probe attack.
This is very annoying and its using up my CPU for nothing...
91.205.41.57 - McCafee
I dont know about you but i feel like McAfee is trying to make me buy their antivirus by scaring me with this notification, because i have 4 days left to use it for free. I have used McAfee for 3 mont...
202.166.201.118 - srx attacks
Apr 15 14:52:27 sshd[6580]: Received disconnect from 202.166.201.118: 11: Bye ByeApr 15 14:52:34 sshd[6581]: Failed password for root from 202.166.201.118 port 45834 ssh2Apr 15 14:52:35 sshd[658...
98.136.145.193 - trying to connect on port 81
4 times in 2 minutes. This is supposedly in California and started within 1 minutes of registering on ipillion. Most attacks are from apnic or lacnic areas...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Apr 13 01:32:48 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Apr 15 06:41:08 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
82.8.198.72 - HackAttack: [SPI:Illegal connection state attack]
Apr 15 04:57:32 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 82.8.198.72 to 80.220.22.74
Apr 15 04:57:35 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
206.74.204.145 - HackAttack: [SPI:Illegal connection state attack]
Apr 15 01:30:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 206.74.204.145 to 80.220.22.74
Apr 15 01:30:29 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
50.97.97.41 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 11 02:13:19 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.97.97.41 to 80.220.22.74
Apr 14 23:31:11 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
108.170.16.14 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 14 00:10:14 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.170.16.14 to 80.220.22.74
Apr 14 13:27:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
24.54.15.45 - HackAttack: [SPI:Illegal connection state attack]
Apr 14 11:35:43 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.54.15.45 to 80.220.22.74
Apr 14 11:35:46 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
89.28.105.61 - Blocked
Is yet another Starnet Communications IP blocked by Malwarebytes
Unsure why but Malwarebytes keeps blocking this and other Starnet Communication IP\'s, have been several just today...
198.228.234.76 - intrusion attempts
My Firewall F-Secure me constantly displays repetitive alerts regarding intrusion attempts from this IP: 198.228.234.76. Today April 13, 2012, I had 16 intrusion attempts. Thank you...
92.114.86.101 - HackAttack: [SPI:Illegal connection state attack]
Apr 13 22:33:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.114.86.101 to 80.220.22.74
Apr 13 22:37:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
89.28.109.193 - Blocked
By Malwarebytes and is another IP from Starnet Communications and not sure why they are blocked but alot of IP\'s from Starnet are blocked by Malwarebytes...
89.28.186.252 - Blocked
Malwarebytes is blocking this IP and am not sure why, is UK IP for Willis Group Services Ltd which does insurance so really don\'t know why they are blocked...
89.28.51.45 - Blocked by Malwarebytes
Is another IP from China and is Starnet Communications but haven\'t @ this time found why they are blocked but other Starnet IP\'s are being blocked as well...
117.21.221.91 - Blocked by Malawarebytes
Not sure why Malwarebytes blocked this IP so is why category under firewall alert
I dunno who they are or why they are blocked, and blocked several times...
87.248.186.252 - Malawarebytes blocking this
wasn\'t sure the category as not sure what this is or why is blocked.
Is Starnet Communications & have no idea who they are or why Malwarebytes blocks this......
69.64.34.170 - HackAttack: [SPI:Illegal connection state attack]
Apr 13 00:36:33 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 69.64.34.170 to 80.220.22.74
Apr 13 04:23:47 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
184.107.233.146 - HackAttack: [SPI:Illegal connection state attack]
Apr 12 05:02:49 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 184.107.233.146 to 80.220.22.74
Apr 12 20:19:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
58.218.199.227 - Firewall Alert
They just try to get in, which does not succeed. but the action on its own is not allowed. This makes it 25 words doe sit not?...
89.114.9.96 - outgoing
I\'m not sure exactly what is going on or what information they are trying to retrieve from the affected PC but we got an alert from our Virus Protection software, ran Malware Bytes and got the log be...
85.113.203.84 - HackAttack: [SPI:Illegal connection state attack]
Apr 12 12:04:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 85.113.203.84 to 80.220.22.74
Apr 12 12:04:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
37.157.244.122 - HackAttack: [SPI:Illegal connection state attack]
Apr 12 01:09:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 37.157.244.122 to 80.220.22.74
Apr 12 02:40:11 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
68.68.22.103 - HackAttack: [SPI:Illegal connection state attack]
Feb 20 17:20:54 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.68.22.103 to 80.220.22.74
Apr 11 13:58:31 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
101.12.175.39 - Half-Scan Attack
ISA Server alert: An intrusion was attempted by an external user, ISA Server detected a possible Internet Protocol (IP) half-scan attack from IP address 101.12.175.39....
199.30.80.32 - Hack attack
Why all the pathetic ass**les have activated recently?
Apr 11 10:27:40 HackAttack: [SPI:Illegal connection state attack] TCP packet from [nas0] 199.30.80.32:80 to 77.86.194.26:39093
Apr 11 10:28:00 ...
209.15.236.190 - attempted scan from ZmEu Vulnerability Scanner
The following intrusion was observed: .
date=2012-04-07 time=03:24:22 devname=RM-CT-VPN01 device_id=FGT80C3910606182 log_id=0419016384 type=ips subtype=signature pri=alert severity=low carrier_ep=...
59.34.198.9 - DNS
We are receiving thousands of \'ANY\' queries per second in our DNS servers that coming from this IP.
This situation is in all servers at same time and tries to desynchronize them and take down the s...
95.211.166.56 - HackAttack: [SPI:Illegal connection state attack]
Apr 9 20:30:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 95.211.166.56 to 80.220.22.74
Apr 9 21:23:55 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
50.97.97.41 - HackAttack: [SPI:Illegal connection state attack]
Apr 3 12:23:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.97.97.41 to 80.220.22.74
Apr 9 10:06:28 HackAttack: [SPI:Illegal connection state attack] ICMP packer from...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Apr 7 23:36:19 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Apr 9 06:58:27 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
200.61.40.182 - HackAttack: [SPI:Illegal connection state attack]
Apr 8 13:02:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 200.61.40.182 to 80.220.22.74
Apr 8 13:02:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
58.218.199.147 - my pc
they just tried to get into my pc through my fire wall, major attack, my eset caught it in a flash, the port scanning from the chinese sucks big time :(...
58.218.199.227 - Port Scanning Attack
Informed of port scan attack, of Chinese origin, 8.218.199.227 is in Beijing Beijing China, can this be reported to authorities, as this is the second attack caught by my firewall...
91.213.175.71 - cannot access the website.
i have invested 20$us into diamond-rain.net account for 15 days and when the invested is matured i cannot access the website the investment is from march 23 -april 7 2012 i dont know what is happening...
216.245.202.53 - HackAttack: [SPI:Illegal connection state attack]
Mar 9 05:53:40 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 216.245.202.53 to 80.220.22.74
Apr 8 10:26:18 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
207.161.39.54 - Port scanning? couple of days now
Apr 8 09:16:10 HackAttack: [SPI:Illegal connection state attack] TCP packet from [nas0] 207.161.39.54:51111 to 77.86.194.26:63957
Apr 8 09:16:10 HackAttack: [SPI:Illegal connection state attack] TC...
174.57.0.143 - HackAttack: [SPI:Illegal connection state attack]
Apr 8 01:53:36 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.57.0.143 to 80.220.22.74
Apr 8 01:53:36 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
82.98.147.22 - trying to login
this ip is been trying to login to my website thru the backend using random passwords , i have receive about 50 intents to enter in the last 8 hours...
174.57.0.143 - HackAttack: [SPI:Illegal connection state attack]
Apr 7 23:32:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.57.0.143 to 80.220.22.74
Apr 7 23:32:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
46.201.77.97 - HackAttack: [SPI:Illegal connection state attack]
Apr 7 20:00:08 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 46.201.77.97 to 80.220.22.74
Apr 7 20:00:08 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
96.10.158.224 - HackAttack: [SPI:Illegal connection state attack]
Apr 7 11:01:56 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 96.10.158.224 to 80.220.22.74
Apr 7 11:01:56 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
174.57.0.143 - HackAttack: [SPI:Illegal connection state attack]
Apr 7 10:21:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.57.0.143 to 80.220.22.74
Apr 7 10:22:00 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
195.3.147.99 - 195.3.147.99
Repeated attempts to gain accesss. Blocked by Malwarebytes as malicious Website. Port 5428 Chrome.exe. Want to find out who this is and how to stop it compltely....
96.10.158.224 - HackAttack: [SPI:Illegal connection state attack]
Apr 7 10:01:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 96.10.158.224 to 80.220.22.74
Apr 7 10:01:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
96.10.158.224 - HackAttack: [SPI:Illegal connection state attack]
Apr 6 23:48:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 96.10.158.224 to 80.220.22.74
Apr 6 23:48:47 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
174.57.0.143 - HackAttack: [SPI:Illegal connection state attack]
Apr 6 23:38:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.57.0.143 to 80.220.22.74
Apr 6 23:38:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
195.3.147.99 - Firefox keeps trying to access this IP
Among 3 others
Malawarebytes is reporting this as a malicious website and blocks firefox from accessing it
Am trying to find out \'what\' is trying to access this......is this and 3 other IP\'s over ...
58.218.199.87 - Daily
Fri Apr 6 13:39:42 2012
=>Found attack from 58.218.199.87.
Source port is 12200 and destination port is 6515 which use the TCP protocol. Happens regularly. Getting s/w to gather more info....
24.202.23.227 - HackAttack: [SPI:Illegal connection state attack]
Apr 6 12:25:27 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.202.23.227 to 80.220.22.74
Apr 6 12:25:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
91.121.3.57 - HackAttack: [TCP SYN Flooding]
Apr 6 11:08:40 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 91.121.3.57:6664 to 80.220.22.74:6664
Apr 6 11:08:40 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 91.121.3.57:6666 to 8...
66.35.46.196 - UDP Port Attacks
I\'ve getting this UDP Port attacks with Different Ports.
Blocked incoming UDP packet from 66.35.46.196:10670
Above message repeated 9 times
Blocked incoming UDP packet from 66.35.46.196:12254
Above...
110.34.131.115 - HackAttack: [SPI:Illegal connection state attack]
Apr 5 16:54:28 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 110.34.131.115 to 80.220.22.74
Apr 5 17:42:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
221.192.199.49 - IP block
Incoming block form Malwarebytes. Count at least 157 attempts over the past few days. Some people are only alive today because it\'s illegal to kill...
60.190.222.185 - IP blocked
comes from China. Bloody annoying. At least 6 attempts a day. Wish they would just fuck off and do something constructive instead of annoy me...
63.223.106.17 - hacker
stop this person from trying to get in my computer, it seems like malwarebytes trying to block them but it doesnt feel safe anymore. it\'s also irritating.. please shut this IP down....
91.217.178.18 - Antivirus blocked attempt
antivirus is reporting that it is blocking a connection from this site, which is appearant that I have no desire for contact to or from it....
88.190.30.80 - Hacker!
This hacker had access to my network last saturday. See my firewall log:
[LAN access from remote] from 88.190.30.80:56134 to 10.0.0.99:81, Saturday, March 31,2012 13:07:37
I will trace you !
...
78.148.72.122 - HackAttack: [SPI:Illegal connection state attack]
Apr 4 20:42:47 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 78.148.72.122 to 80.220.22.74
Apr 4 20:42:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
78.148.72.122 - HackAttack: [SPI:Illegal connection state attack]
Apr 4 20:12:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 78.148.72.122 to 80.220.22.74
Apr 4 20:12:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
199.115.228.202 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 4 02:57:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 199.115.228.202 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/199.115.228.202 RESULT:
199.115.228.202...
122.226.86.84 - HackAttack: [SPI:Illegal connection state attack]
Apr 4 00:15:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 122.226.86.84 to 80.220.22.74
Apr 4 02:45:58 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
122.226.86.105 - HackAttack: [SPI:Illegal connection state attack]
Apr 4 02:26:01 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 122.226.86.105 to 80.220.22.74
Apr 4 02:37:27 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
176.227.211.98 - HackAttack: [SPI:Illegal connection state attack]
Apr 4 01:06:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 176.227.211.98 to 80.220.22.74
Apr 4 03:57:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
108.170.43.10 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 3 22:49:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.170.43.10 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/108.170.43.10 RESULT:
108.170.43.10 IP add...
108.170.42.250 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 3 19:03:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.170.42.250 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/108.170.42.250 RESULT:
108.170.42.250 IP...
93.184.216.119 - Outbound connection to 93.184.216.119
I just booted the computer, fresh start, I have been having issues with my network, it seems just too slow.. or it just doesn\'t connect at all.
So exploring the log in my router it had that as a cur...
108.170.43.2 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 3 18:43:07 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.170.43.2 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/108.170.43.2 RESULT:
108.170.43.2 IP addre...
176.227.211.98 - Attacks from h176-227-211-98.host.redstation.co.uk
Apr 4 01:31:42 Hack Attack: DROP ICMP packet from [nas0] 176.227.211.98 to 77.86.xxx.xxx <SPI:Illegal connection state attack>
I keep getting firewall alerts like this all the time. Started at...
176.227.211.181 - HackAttack: [SPI:Illegal connection state attack]
Apr 3 17:35:05 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 176.227.211.181 to 80.220.22.74
Apr 3 17:35:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
75.60.174.97 - HackAttack: [SPI:Illegal connection state attack]
Apr 3 11:25:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 75.60.174.97 to 80.220.22.74
Apr 3 11:25:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
37.59.88.209 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 3 04:50:32 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 37.59.88.209 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/37.59.88.209 RESULT:
37.59.88.209 IP addre...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Apr 3 02:26:40 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Apr 3 02:43:07 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
176.14.58.90 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 2 22:27:23 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 176.14.58.90 to 80.220.22.74
Apr 2 22:27:23 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
174.138.210.63 - HackAttack: [SPI:Illegal connection state attack]
Apr 2 12:14:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.138.210.63 to 80.220.22.74
Apr 2 12:14:54 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
174.49.76.73 - HackAttack: [SPI:Illegal connection state attack]
Apr 2 10:14:21 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.49.76.73 to 80.220.22.74
Apr 2 10:14:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
108.170.22.70 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 2 08:16:35 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.170.22.70 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/108.170.22.70 RESULT:
108.170.22.70 IP ad...
87.117.252.238 - HackAttack: [SPI:Illegal connection state attack]
Apr 2 04:06:50 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 87.117.252.238 to 80.220.22.74
Apr 2 05:50:54 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
176.227.211.180 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 2 00:31:48 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 176.227.211.180 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/176.227.211.180 RESULT:
176.227.211.180...
109.200.9.146 - HackAttack: [SPI:Illegal connection state attack]
Mar 28 02:22:21 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 109.200.9.146 to 80.220.22.74
Mar 29 18:46:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
101.123.34.123 - HELP PLEASE
MY COMPUTER IS MAKING WEIRD NOISES. AND EVERY 5 MINUTES SECURITY ALERT COME UP WITH THE IP # 101.123.34.123
I DON\'T KNOW WHERE THIS IS COMING FROM BUT PLEASE HELP ME...
91.226.78.130 - IP Address - 91.226.78.130
McAfee continues to give warnings that it has blocked this IP address from making a connection to my computer - happens 2 to 4 times a week....
61.128.162.4 - NETWORK ATTACK
THIS IP ADDRESS ATTACK TO MY COMPUTR BUT BLOCK KIS 2012
DETAIL BELOW
Intrusion.Win.MSSQL.worm.Helkern Undefined 4/2/2012 2:08:48 AM
PLEASE HELP ME
WHAT IS THIS VIRUS OR HACKER
JAGJEEWAN YADAV IN UP...
93.114.46.158 - 93.114.46.158 complaint
This IP (lh17590.limehost.ro) tried to remote dedktop to my computer for no apparrent reason. This may be an accident but I though\'t I would notify you....
176.227.211.181 - HackAttack: [SPI:Illegal connection state attack] + INFO
Apr 1 01:02:26 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 176.227.211.181 to 80.220.22.74
Apr 1 18:58:28 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
31.3.225.146 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 31 23:26:46 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 31.3.225.146 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/31.3.225.146 RESULT:
31.3.225.146 IP addr...
Please banned this IP as they are trying to hack our Firewall and Network.
Message meets Alert condition
time april 01 2012 19:32 to april 01 2012 20:42
system,error,critical login failure for user ro...
183.64.202.67 - Trying to login
This adress is trying to acces our network firewalls. i have this from our zywall.
146 2012-03-31 23:35:06 alert User Failed login attempt to ZyWALL from ssh (incorrect password or inexistent usernam...
173.212.195.174 - Brandon Beachy Jersey
http://www.bravesproshop.com/24-phil-niekro-jersey Phil Niekro Jersey
http://www.bravesproshop.com/19-diaz-matt-jersey Diaz Matt Jersey
http://www.bravesproshop.com/16-dale-murphy-...
66.35.46.196 - Constant UDP Port Attacks
I have been getting constant UDP port attacks by IP\'s 66.35.46.196 and 66.35.46.197 , today there has been over 3300 port attempts
FWIN,2012/03/30,20:46:32 -4:00 GMT,66.35.46.197:15210,173.176.20.1...
108.170.9.122 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 30 23:54:50 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.170.9.122 to 80.220.22.74
Mar 30 23:55:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
82.192.92.65 - HackAttack: [SPI:Illegal connection state attack]
Mar 25 10:31:04 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 82.192.92.65 to 80.220.22.74
Mar 28 21:58:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Mar 30 04:51:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Mar 30 17:07:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
58.218.199.147 - Constant port scan attemps
This ip constantly attemps port scans. 58.218.199.147 Never stops over and over, From what I found origin china. MUST BE STOPPED, DANGEROUS, NOT SAFE, VERY AGGRIVATING, ENOUGH IS ENOUGH!!!!...
208.79.211.11 - Fri 2012-03-30 17:49:59 TCP flood From 208.79.211.112 port:60597 To 78.149.69.134 port:6881
I have many flood warnings in my firewall log. Can you please have a look into this for me please. Thanks very much ...
217.118.24.95 - SSH
multiple attempts to SSH on to all available IP addresses from loft2293.serverloft.com (217.118.24.95) - unsuccessful this time . . . . . . . . . . ....
206.161.121.4 - access blocked - "malicious website" warning
Have been experiencing repeated alerts that say something about access to malicious website (206.161.121.4) being blocked. Other alerts for 89.114.9.97 alternate. Would like to know if there is a cu...
175.36.104.11 - HackAttack: [SPI:Illegal connection state attack]
Mar 30 09:21:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 175.36.104.11 to 80.220.22.74
Mar 30 09:21:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
78.138.97.122 - HackAttack: [SPI:Illegal connection state attack]
Mar 30 01:34:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 78.138.97.122 to 80.220.22.74
Mar 30 05:14:54 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
174.97.155.41 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 22:08:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.97.155.41 to 80.220.22.74
Mar 29 22:08:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
184.173.232.14 - HackAttack: [SPI:Illegal connection state attack] +INFO
Mar 29 20:04:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 184.173.232.14 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/184.173.232.14 RESULT:
184.173.232.14 IP...
2.120.167.166 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 16:33:27 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 2.120.167.166 to 80.220.22.74
Mar 29 16:33:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
195.175.240.98 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 16:05:43 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 195.175.240.98 to 80.220.22.74
Mar 29 17:22:26 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
09.114.9.97 - virus?
This IP address is being block by my walware bytes. I revieved it after going to look for hotels on priceline.com in the washington area...
24.125.160.148 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 15:18:14 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.125.160.148 to 80.220.22.74
Mar 29 15:18:17 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
174.97.155.41 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 14:34:50 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.97.155.41 to 80.220.22.74
Mar 29 14:34:53 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
24.125.160.148 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 12:09:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.125.160.148 to 80.220.22.74
Mar 29 12:09:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
174.97.155.41 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 11:39:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.97.155.41 to 80.220.22.74
Mar 29 11:39:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
76.93.48.132 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 10:56:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 76.93.48.132 to 80.220.22.74
Mar 29 10:56:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
76.93.48.132 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 09:55:59 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 76.93.48.132 to 80.220.22.74
Mar 29 09:55:59 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
24.125.160.148 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 09:51:01 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.125.160.148 to 80.220.22.74
Mar 29 09:51:04 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
190.194.65.237 - 190.194.65.237
I wish to submit a complaint about this IP address which sent a virus to my computer yesterday at about midday. I have now deleted the e-mail. The owner of this address seems to be Prima SA and the ...
174.97.155.41 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 09:19:46 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.97.155.41 to 80.220.22.74
Mar 29 09:19:46 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
76.93.48.132 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 05:43:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 76.93.48.132 to 80.220.22.74
Mar 29 05:43:50 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
24.125.160.148 - HackAttack: [SPI:Illegal connection state attack]
Mar 29 01:49:18 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.125.160.148 to 80.220.22.74
Mar 29 01:49:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
24.125.160.148 - HackAttack: [SPI:Illegal connection state attack]
Mar 28 23:31:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.125.160.148 to 80.220.22.74
Mar 28 23:31:29 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
92.48.74.32 - HackAttack: [SPI:Illegal connection state attack]
Mar 28 22:35:34 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.48.74.32 to 80.220.22.74
Mar 28 22:59:32 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
174.97.155.41 - HackAttack: [SPI:Illegal connection state attack]
Mar 28 22:23:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.97.155.41 to 80.220.22.74
Mar 28 22:23:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
174.97.155.41 - HackAttack: [SPI:Illegal connection state attack]
Mar 28 11:47:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.97.155.41 to 80.220.22.74
Mar 28 11:47:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
91.217.66.245 - HackAttack: [SPI:Illegal connection state attack]
Mar 28 05:09:47 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 91.217.66.245 to 80.220.22.74
Mar 28 05:09:47 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
109.230.216.211 - HackAttack: [SPI:Illegal connection state attack]
Mar 27 23:24:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 109.230.216.211 to 80.220.22.74
Mar 27 23:56:36 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
221.192.199.49 - hackers?
Somebody is scanning your computer.
Your computer\'s TCP ports:
27977, 1080, 8085, and 8008 have been scanned from 221.192.199.49..
This is a firewall log. It happens every 2 hours...
109.200.9.146 - HackAttack: [SPI:Illegal connection state attack]
Mar 27 15:09:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 109.200.9.146 to 80.220.22.74
Mar 27 15:26:26 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
218.240.23.102 - NAS attack
After installation of IP camera from dealextreme to internal LAN, my NAS recorded a lot of access to administrator account. Finally automatically blocked by IP filtering. Don\'t use the same account ...
173.236.50.235 - complaint hig alert from I.P. 173.236.50.235
Above I.P. attacked my computer targeting files. Attempt overted by security software. Malicious tool kit. Please shut them down. Thank you very much for your time. ...
183.203.11.199 - HackAttack: [SPI:Illegal connection state attack]
Mar 26 15:57:59 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 183.203.11.199 to 80.220.22.74
Mar 26 15:57:59 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
176.227.221.2 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 26 08:04:32 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 176.227.221.2 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/176.227.221.2 RESULT:
176.227.221.2 IP ad...
41.138.179.52 - Attack
This IP address (41:138.179.52) is constantly attacking my computer and attempting to hack into my system. The last attack on my system was made today monday march 26, 2012 at 6.39pm...
94.200.165.242 - RDP cracking
This arse wipe has been trying to crack an account on our RDP server for bast part of two weeks now. scumbag rectum flaps - 25 words....really?...
188.87.38.178 - HackAttack: [SPI:Illegal connection state attack]
Mar 25 23:56:01 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 188.87.38.178 to 80.220.22.74
Mar 25 23:56:01 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
109.73.76.216 - HackAttack: [SPI:Illegal connection state attack]
Mar 25 18:20:49 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 109.73.76.216 to 80.220.22.74
Mar 25 19:24:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
109.200.9.146 - HackAttack: [SPI:Illegal connection state attack]
Mar 23 05:48:59 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 109.200.9.146 to 80.220.22.74
Mar 25 13:35:23 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
173.236.50.235 - Web Attack: Malicious Toolkit Website 9
Got this flagged from Norton. It said the traffic from this address matches the signature of a known attack. It also said the attack was resulted from \\DEVICE\\HARDDISKVOLUME2\\PROGRAM FILES (X86)\...
94.245.121.253 - FIrewall
FIrewall has gone off its head constantly advising this IP is trying to make a connection
Protocol UDP Source IP: 94.245.121.253:3544
FIrewall has gone off its head constantly advising this IP is ...
58.218.199.147 - It's a proxy
This IP is a transparent proxy. You think it\'s one dude, but it\'s a ton of innocent folks connecting behind this very same proxy.
And 26....
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Mar 24 04:38:54 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Mar 24 22:51:46 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
37.59.160.242 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 24 14:36:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 37.59.160.242 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/37.59.160.242 RESULT:
37.59.160.242 IP ad...
64.15.147.48 - Received a notification from Malware Bytes
Received a notification from Malware Bytes that the IP 64.15.147.48 has been blocked because of malicious activity on my computer.
Please send details of website to gaurav.agarwl@gmail.com...
206.161.121.5 - 206.161.121.5
malicious website is trying to access your computer...that is the message that I get. I am so tired of it. It has been doing this all night. Please stop...
72.90.75.34 - Service Blocked ICMP echo req
Here is the info for the ip adress
IP Address: 72.90.75.34
IP Address Country: United States (US)
IP Address Region: NY New York
IP Address City: Liverpool
IP Postal Code 13088
IP Address Area Code...
24.52.74.197 - Service Blocked ICMP ech req
reporting this ip adress here is it\'s info IP Address: 24.52.74.197
IP Address Country: United States (US)
IP Address Region: OH Ohio
IP Address City: Toledo
IP Postal Code 43614
IP Address Are...
58.218.199.250 - Attempted connection
This one tried more than once to hook-up with my ip address, attack on my computer trying to scan my ports... im not happy about this...
176.9.140.35 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 23 21:26:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 176.9.140.35 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/176.9.140.35 RESULT:
176.9.140.35 IP addres...
174.123.254.66 - HackAttack: [SPI:Illegal connection state attack]
Feb 21 14:29:38 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.123.254.66 to 80.220.22.74
Mar 23 12:05:39 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
61.235.46.146 - They Just want to hack but couldnt !
I ve been attacked By one computer or more (I dont know ) But thanks God I was using Kaspersky and it did the Best as usual and I have to say keep using that and keep it update Too !! Take care Guys ...
94.245.121.253 - Constant request from this IP
FIrewall has gone off its head constantly advising this IP is trying to make a connection
Protocol UDP Source IP: 94.245.121.253:3544
FIrewall has gone off its head constantly advising this IP is t...
206.161.121.3 - 206.161.121.3
It seems this is a constant malware threat that keeps being blocked by my firewall. It is tagged as an outgoing message. Seems to be in my system....
67.22.130.17 - HackAttack: [SPI:Illegal connection state attack]
Mar 22 23:45:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 67.22.130.17 to 80.220.22.74
Mar 22 23:45:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
173.214.160.48 - 173.214.160.48
Silencer Trojan Horse \"attempted to access internet\" message received from Norton. According to a search for the ip on Google, the ip is located in New Jersey, USA....
109.200.9.146 - HackAttack: [SPI:Illegal connection state attack]
Mar 22 17:04:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 109.200.9.146 to 80.220.22.74
Mar 22 18:22:56 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
58.218.199.227 - Router alert
There are multiple alert entries like that:
kernel: Intrusion -> IN=ppp_1_32_1 OUT= MAC= SRC=58.218.199.227 LEN=40 TOS=0x00 PREC=0x00 TTL=113 ID=256 DF PROTO=TCP SPT=12200 DPT=8080 WINDOW=8192 RES...
58.218.199.227 - port scanning from 58.218.199.227
I\'ve been seeing port scans from this ip address hitting my router. It says their source port is 12200. I\'m seeing attempted destination port scans ranging from 80 to 27977....
128.9.160.132 - Network Attack Notification
43 attempts from this ip address in 7 hour period today alone.
Following Info in firewall log:
Notice Network Access ICMP packet dropped due to policy 128.9.160.132, 869, X1 ICMP Echo, Code: 0 ...
192.168.1.6 - a girl
a boy sayd mani bad things abut mi famili and said bad words of me and tell me that go to have sex with me :(...
190.144.55.163 - a boy
he tall much bad words about mi mother and mi father this is the problem that i have now i need 100 millions ...
148.243.142.18 - help!!!!
Hi there,
How can u help? After installing ZoneAlarm I realized that most of the attacks or knock on my door are from telecoms, or huge Internet companies \'round the world.
I wonder how can this b...
58.218.199.227 - ABUSE FROM 58.218.199.227
For weeks now, someone from this address has been probing my network, attempting to compromise my firewall, dmz machines and penetrate my LAN.
Incidents have been occurring hourly for over two weeks....
66.185.85.155 - Outgoing Access To this IP from svchost.exe
For some reason I cannot trace this IP back to a host such as microsoft, but I do know svchost.exe network services is trying to connect to here. I know I could be mistaken, but this is strange. I saw...
206.161.121.3 - My system is trying to contact this IP address
I\'ve noticed that I have had a runaway svchost.exe for a time and in trying to stop it I\'ve purchased several programs. It seems that something on my system is trying to contact these people and my...
173.192.170.85 - HackAttack: [SPI:Illegal connection state attack]
Mar 18 17:43:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 173.192.170.85 to 80.220.22.74
Mar 18 17:43:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
61.235.46.146 - Stop it.
Network attack Intrusion.Win.MSSSQL.worm.Helkern on local port 15454.
1 attempt on my desktop, another 5-7 attempts on my laptop. =.=
Looks like China have the most time on hacking..... -.-...
64.212.114.89 - attempted unauthorized connection
A user at 64.212.114.89 broke through my routers firewall and was blocked when he/she tried to access my laptop it is possible the user in question broke into my home server as it is not currently ru...
68.44.141.222 - HackAttack: [SPI:Illegal connection state attack]
Mar 17 08:49:17 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.44.141.222 to 80.220.22.74
Mar 17 09:29:32 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Mar 14 02:37:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Mar 17 10:14:43 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
58.218.199.147 - 58.218.199.147
port scanning attack, that is all I know , I have recieved two alerts from my security system that this same IP has tried to break through my fire wall...
91.217.178.18 - multiple attempts to log into my network
someone from this address is trying to get in to my server and this ip address is unknown to me. there were multiple attempts to get into my system...
109.120.156.200 - Scan Ports
[INFO] Wed Mar 14 10:16:41 2012 Blocked incoming TCP connection request from 109.120.156.200:56599 to 109.173.114.61:13500
[INFO] Wed Mar 14 10:16:39 2012 Blocked incoming TCP connection request from ...
60.217.235.5 - attacks to our server
This IP is trying to brut force its way through our ssh servers. This ip was blocked by our firewall. I wonder why the providers don\'t just close this suckers services......
61.235.46.146 - Kaspersky Internetsecurity meldet Netzwerkangriff
Netzwerkangriff auf lokalen Port 1434 von der IP-Adresse 61.235.46.146
wurde verboten: intrusion.Win.MSSSQL.worm.Helkern
Datum: 14.03.2012 Uhrzeit: 10:54
Von China kommen immer wieder solche Netzwerk...
71.194.98.98 - HackAttack: [SPI:Illegal connection state attack]
Mar 13 22:38:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 71.194.98.98 to 80.220.22.74
Mar 13 22:38:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
98.221.72.31 - HackAttack: [SPI:Illegal connection state attack]
Mar 13 22:18:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 98.221.72.31 to 80.220.22.74
Mar 13 22:18:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
71.194.98.98 - HackAttack: [SPI:Illegal connection state attack]
Mar 13 17:39:36 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 71.194.98.98 to 80.220.22.74
Mar 13 17:39:40 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
98.221.72.31 - HackAttack: [SPI:Illegal connection state attack]
Mar 13 17:30:02 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 98.221.72.31 to 80.220.22.74
Mar 13 17:30:02 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
206.161.121.5 - Complaint web site attacking my computer
206.161.121.2
206.161.121.4
206.161.121.5
this site bombards my computer all day and nite, my firewall stops the intrusion this is very annoying i do not know what they want or what they are trying t...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Mar 12 22:04:32 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Mar 13 03:10:48 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
93.89.92.20 - HackAttack: [TCP SYN Flooding]
Mar 13 00:05:21 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 93.89.92.20:6663 to 80.220.22.74:6663
Mar 13 00:05:21 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 93.89.92.20:6664 to 8...
58.218.199.227 - Portscan Attempt
Been getting scanned every 5 minutes or so, really annoying. Antivirius detects and prevents the scan but still could be dangerous. Could be spies also :)
...
68.68.29.204 - HackAttack: [SPI:Illegal connection state attack]
Mar 12 19:29:02 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.68.29.204 to 80.220.22.74
Mar 12 20:43:28 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
189.73.205.184 - HackAttack: [SPI:Illegal connection state attack]
Mar 12 16:16:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 189.73.205.184 to 80.220.22.74
Mar 12 16:16:31 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
189.73.205.184 - HackAttack: [SPI:Illegal connection state attack]
Mar 12 09:43:34 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 189.73.205.184 to 80.220.22.74
Mar 12 09:43:35 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
202.228.239.196 - SSH password probe
sshd[50656]: Failed password for root from 202.228.239.196 port 41228 ssh2
sshd[42420]: Failed password for root from 202.228.239.196 port 41111 ssh2
sshd[29342]: Failed password for root from 202.22...
61.253.249.157 - SSH login attempt
Failed password for root from 61.253.249.157 port 42455 ssh2
Failed password for root from 61.253.249.157 port 42455 ssh2
Failed password for root from 61.253.249.157 port 42455 ssh2
(3 Attempts total...
206.161.121.5 - 206.161.121.5 and 67.29.139.253 attact at the same time
73.236.56.93 (Type: outgoing)
2012/03/11 10:05:35 -0400 IP-BLOCK 206.161.121.3 (Type: outgoing)
2012/03/11 10:05:37 -0400 IP-BLOCK 206.161.121.4 (Type: outgoing)
2012/03/11 10:05:38 -0400 IP-BLO...
189.1.162.6 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 11 11:15:28 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 189.1.162.6 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/189.1.162.6 RESULT:
189.1.162.6 IP address l...
176.9.113.49 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 11 03:04:01 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 176.9.113.49 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/176.9.113.49 RESULT:
176.9.113.49 IP addre...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Mar 7 19:09:05 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Mar 11 00:50:18 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
213.180.92.129 - tcp data on syn segment
Same complaint by me.
From recent log:
Mar 9 20:49 GMT.
IDS proto parser : tcp data on syn segment (1 of 1) : 213.180.92.129 x.x.x.x 0060 TCP 50674->8827 [S.....] seq 224067651 win 32120...
216.245.200.20 - HackAttack: [SPI:Illegal connection state attack]
Mar 10 10:18:48 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 216.245.200.20 to 80.220.22.74
Mar 10 14:41:04 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
202.98.29.19 - trying to hack...
Mar 9 21:55:04 fw sshd[27452]: Invalid user oracle from 202.98.29.19
Mar 9 21:55:07 fw sshd[27489]: Invalid user oracle from 202.98.29.19
Mar 9 21:55:11 fw sshd[27491]: Invalid user oracle from 202...
117.243.250.249 - try it multiple times...
Mar 7 02:53:16 fwsshd[19425]: Invalid user shelluser from 117.243.250.249
Mar 7 02:53:21 fwsshd[19437]: Invalid user maxion from 117.243.250.249
Mar 7 02:53:26 fwsshd[19451]: Invalid user shelluser...
58.218.199.147 - Log report
58.218.199.147 - - [09/Mar/2012:12:25:24] \"GET /judge.php HTTP/1.1\" 401 739 \"\" \"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)\"
58.218.199.147
58.218.199.147 -...
58.218.199.250 - Still at it !
Log entry :
58.218.199.250 - - [09/Mar/2012:09:09:27] \"GET /me/proxyheader.php HTTP/1.1\" 401 739 \"\" \"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)\"
58.218.19...
173.192.176.155 - HackAttack: [SPI:Illegal connection state attack]
Mar 8 09:02:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 173.192.176.155 to 80.220.22.74
Mar 9 10:21:23 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
94.23.213.102 - HackAttack: [TCP SYN Flooding]
Mar 9 17:25:06 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 94.23.213.102:6662 to 80.220.22.74:6662
Mar 9 17:25:06 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 94.23.213.102:6664 ...
213.180.92.129 - tcp data on syn segment
IDS proto parser : tcp data on syn segment (1 of 1) : 213.180.92.129 81.228.154.22 0060 TCP 36083->14272 [S.....] seq 3031957571 win 32120
...no need of this!!...
58.218.199.227 - "#$$%#%#"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 58.218.199.227
IP destination address : 76.227.65.191
Number of attempts ...
31.170.161.183 - Intrusion Attempt
Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Addre...
58.218.199.227 - "Can't Get Enough"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 58.218.199.227
IP destination address : 76.227.65.191
Number of attempts ...
64.31.63.116 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 8 18:16:35 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 64.31.63.116 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/64.31.63.116 RESULT:
4.31.63.116 IP address...
95.67.191.189 - HackAttack: [SPI:Illegal connection state attack]
Mar 8 12:38:52 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 95.67.191.189 to 80.220.22.74
Mar 8 12:38:52 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
58.218.199.227 - Port scanner
He has done this to me today as well, multipal times.
Its rather annoying but he is being blocked each time.
Tried changing IP that didnt work, any other suggestions?...
65.97.63.247 - Constant pinging
IP keeps pinging port 52730 over and over again for the last hour. Seems to really want through for some reason. Anyone else have this issue? ...
Went to a site unrelated to this and this ip tried to access my computer. Malwarebytes blocked it, but the ip is continually trying to access my computer. It has so far attempted to access my comput...
208.43.15.198 - HackAttack: [SPI:Illegal connection state attack]
Mar 4 21:20:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 208.43.15.198 to 80.220.22.74
Mar 7 14:49:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
69.64.36.29 - IP Block 69.64.36.29
HELP!!!! I need to get rid of this!! It is a pain and i have tried everything! Is there a solution!!?
IP Block 69.64.36.29
Type: outgoing
Port: 59196
Process: chrome.exe
...
195.216.243.184 - IP block 195.216.243.41
The same problem! how can i get it to stop or eliminate whatever its causing it!??? It\'s a real pain! Help!!!
IP-BLOCK 195.216.243.41, Type: Outgoing, Port: 59298, Process: chrome.exe...
208.115.226.212 - HackAttack: [SPI:Illegal connection state attack]
Mar 7 20:14:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 208.115.226.212 to 80.220.22.74
Mar 7 20:59:41 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
69.23.112.164 - HackAttack: [SPI:Illegal connection state attack]
Mar 7 19:09:40 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 69.23.112.164 to 80.220.22.74
Mar 7 19:09:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
86.21.14.209 - HackAttack: [TCP SYN Flooding]
Mar 7 17:32:07 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 86.21.14.209:1096 to 80.220.22.74:8118
Mar 7 17:32:17 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 86.21.14.209:1092 to...
149.255.37.55 - HackAttack: [TCP SYN Flooding]
Mar 6 20:14:55 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 149.255.37.55:58152 to 80.220.22.74:3127
Mar 6 20:14:55 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 149.255.37.55:5683...
78.29.15.137 - 78.29.15.137 Trying to hack my Joomla sites
The ip address, 78.29.15.137 keeps trying to hack my backend Administrator on my Joomla websites. What can be done about this? I am using RSFirewall and get constant emails of the attempts....
61.235.46.146 - MS02-039_SQL_SERVER_RESOLUTION_EXPLOIT
2/6/12 7:34 AM MS02-039_SQL_SERVER_RESOLUTION_EXPLOIT 61.235.46.146
2/8/2012 1:28 AM MS02-039_SQL_SERVER_RESOLUTION_EXPLOIT 61.235.46.146
2/9/2012 1:25 PM MS02-039_SQL_SERVER_RESOLUTION_EXPLOIT 61.2...
218.75.49.242 - MS02-039_SQL_SERVER_RESOLUTION_EXPLOIT
These assholes have been trying to hack my customers. Here is part of the security log from one of them.
2/8/2012 9:20 AM MS02-039_SQL_SERVER_RESOLUTION_EXPLOIT 218.75.49.242
2/19/2012 2:57 PM MS02-...
173.236.50.235 - web attack
I had a warning Web attack malicious tool kit website 9 detected from IP address 173.236.50.235. This happened about 6 days ago. please look into it...
144.232.24.202 - HackAttack: [SPI:Illegal connection state attack]
Mar 6 14:56:58 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 144.232.24.202 to 80.220.22.74
Mar 6 15:10:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
188.122.95.81 - HackAttack: [SPI:Illegal connection state attack]
Feb 7 01:47:33 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 188.122.95.81 to 80.220.22.74
Feb 22 13:06:01 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
108.170.21.186 - HackAttack: [SPI:Illegal connection state attack] +INFO
Mar 6 04:17:17 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.170.21.186 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/108.170.21.186 RESULT:
108.170.21.186 IP...
173.255.132.86 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 6 02:48:55 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 173.255.132.86 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/173.255.132.86 RESULT:
173.255.132.86 IP...
61.235.46.146 - Hey hey
I don\'t give a damn.. fuck you yellow people that are trying to get to my comp.. Guess you fucking burn in hell you tiny dicks.....
176.31.230.90 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 5 18:29:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 176.31.230.90 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/176.31.230.90 RESULT:
176.31.230.90 IP add...
98.237.149.87 - HackAttack: [SPI:Illegal connection state attack]
Mar 5 09:01:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 98.237.149.87 to 80.220.22.74
Mar 5 09:02:00 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
77.210.5.151 - scanning ports
Somebody is scanning your computer.
Your computer\'s TCP ports:
9415, 2479, 3246, and 7212 have been scanned from :
1 03/05/2012 15:27:13 Port Scan Incoming TCP 58.218.199.250
2 03/05/2012 16:13...
78.29.15.137 - Trying to hack my Site
Has tried to log into admin area six times without permission. We are sad to see he is doing this with other sites. Whats a jerk
...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Mar 4 19:14:29 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Mar 5 04:04:52 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
78.29.15.137 - Firewall Alert
This ip: 78.29.15.137 is tring to hack into my server. I received reports that this ip has been trying unsuccessfully to login to two domains on my server. ...
46.247.246.227 - HackAttack: [SPI:Illegal connection state attack] + INFO
Mar 4 02:56:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 46.247.246.227 to 80.220.22.74
http://www.ip-adress.com/ip_tracer/46.247.246.227 RESULT:
46.247.246.227 IP...
188.227.181.69 - HackAttack: [SPI:Illegal connection state attack]
Feb 21 01:19:00 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 188.227.181.69 to 80.220.22.74
Mar 4 06:19:53 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
208.91.197.27 - malaware
My computer gets directed to 208.91.196.27.wpad.dat before I even open the browser. It doesn\'t get past the firewall, but continues to try as long as the computer is on...
46.19.37.32 - Silencer trojan horse
I received a Norton message stating an alert was created pertaining to the \"silencer trojan horse\" from the ip 46.19.37.32 about 10 minutes ago (12:25pm Central Time). I\'ve never seen a ...
78.29.15.137 - brute forcing my joomla site.
someone needs to take some serious action against this person(s) who are at this ip address.. I am getting more and more attempts from someone trying to access my site back end.
...
174.36.158.244 - 174.36.158.244
My fire wall is blocking stream of packets going to flynoc.com (under this ip address 174.36.158.244 port 16331). under svchost process
cpu fan is running continuously. I am trying to find the virus.....
149.7.241.51 - unauthorised connection
ip addres was connected to my lan from 192.168.0.102:49156 (printer ip ? ) to : 149.7.241.51 over port 49156
(accidently found out with a netstat -a wjhen my computer was acting funny)...
221.192.199.49 - "Chinese Government Sponsored Hacking"
This IP is working in collaboration with the IP 58.218.199.227
They are scanning for any & all open ports, then they come in with
spam, redirects, virus\'s and try to steal your personal inf...
58.218.199.227 - "Chinese Goverment Sponsored Hacking"
This IP is working in collaboration with the IP 211.192.199.49
They are scanning for any open ports then they come in with
spam, redirects, virus\'s and try to steal your personal information.
...
4.69.148.178 - HackAttack: [SPI:Illegal connection state attack]
Feb 21 17:09:16 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 4.69.148.178 to 80.220.22.74
Mar 2 17:16:07 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Feb 9 10:22:19 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Mar 2 21:49:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
140.113.13.101 - SSH root access
Made more than 200 attempts, 1 per minute to gain access to my server via SSH by trying username root and various passwords before being added to the blocked ip list. Due to the failed attempts and fo...
50.115.119.11 - HackAttack: [SPI:Illegal connection state attack]
Feb 4 04:11:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.115.119.11 to 80.220.22.74
Mar 1 02:42:23 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
117.243.250.249 - This IP is trying to hack our Firewall.
Please banned this IP as they are trying to hack our Firewall and Network.
Message meets Alert condition
date=2012-03-01 time=17:53:07 devname=FG100C3G11600411 device_id=FG100C3G11600411 log_id=010403...
85.90.32.54 - detection of filtering policy
On Feb 29 between 17:27 GMT and 17:31 GMT.
About a dozen attempts of filtering policy detection reported on my firewall. (This is port 33435)...
31.31.77.24 - HackAttack: [TCP SYN Flooding]
Feb 28 19:07:38 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 31.31.77.24:6665 to 80.220.22.74:6665
Feb 28 19:07:38 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 31.31.77.24:6666 to 8...
50.22.69.92 - HackAttack: [SPI:Illegal connection state attack]
Feb 28 04:24:34 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.22.69.92 to 80.220.22.74
Feb 28 04:24:34 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
192.41.11.210 - HackAttack: [SPI:Illegal connection state attack]
Feb 27 19:19:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 192.41.11.210 to 80.220.22.74
Feb 28 20:19:05 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
91.226.78.129 - "LLC Komplit Plyus" IP 91-226-78-138
McAfee continues to give warnings that it has blocked this IP address \"from making a connection\" to my computer - happens usually 2x per day - but not every day....
193.107.16.156 - spy
Tray to get into my computer. The firewall stop it. The allert come from one in one minute. Take care of this ! Don\'t let in...
58.218.199.87 - port 12200
constant pinging on port 12200 from IP 58.218.199.87 from china in my firewall log on my router. Added it to a blacklist in the firewall....
218.241.236.109 - Hacker from china
Hacker from china
218.241.236.109
FWIN,2012/02/26,17:32:42 -5:00 GMT,218.241.236.109:13390,00.00.00.00:22,TCP (flags:S)
Same thing happend to me and iam pretty sure it\'s the same guy on port 12200 ip...
198.111.167.162 - Hacker from United States
Firewall alert
Hacker from United States
198.111.167.162
Ssh Detection from my zonealarm firewall
FWIN,2012/02/26,17:32:42 -5:00 GMT,198.111.167.162:51904,00.00.00.00:22,TCP (flags:S)
Well this is an...
68.67.159.206 - outgoing connection blocked by mcafee
Outgoing connection blocked by McAfee. This has happened twice before. What is this IP address up to: Malware, trojan, or the likes? This is the 2nd stopped connection...
2.18.114.110 - all port scan attack
We receive several all port scan attacks from this (and not only this) ip address. Akamai seem to somehow be keen to get inside our network. Not sure why a company like Akamai would want to lower thei...
4.53.42.58 - HackAttack: [SPI:Illegal connection state attack]
Feb 22 02:27:52 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 4.53.42.58 to 80.220.22.74
Feb 27 12:56:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer from...
91.217.153.88 - pp alexy klimenko 91.217.153.88
monday 27 th february 2012 0658 lt
this adress were stopped by antimalwaresbyte and the firewall.
adre4ss whois in ukraine. tried 2 times . It seems that they try to make
very bad acces to other comp...
94.236.93.234 - Website admin access 625 times
Description: There was an unsuccessful attempt to login into the backend section of your website using an unknown username.
Date of event: 27.02.2012 06:02:45
User IP: 94.236.93.234...
221.192.199.49 - "Closing"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
IP destination address : 76.227.65.191
Number of attempts ...
218.18.232.218 - "Gang of Thieves"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 218.18.232.218
IP destination address : 76.227.65.191
Number of attempts : 3
Time at last attempt : 2/27/12 03:26:20 AM
IP b...
115.89.24.180 - "Previous Post Mistake"
My Immediately preceding post is meant for another IP, Sorry bout that! No current problems with 115.89.24.180 Thanks! And in closing I\'d just like to say it\'s a jungle out there!...
115.89.24.180 - "Gang of Thieves"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 218.18.232.218
IP destination address : 76.227.65.191
Number of attempts ...
221.192.199.49 - "AssHole Chink Fuck"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
IP destination address : 76.227.65.191
Number of attempts ...
221.192.199.49 - "Continuous Harrassment"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
IP destination address : 76.227.65.191
Number of attempts ...
94.72.95.2 - ICMP Attack
Eset has detected an ICMP Attack on my computer from this adress. He is from Lublin in Poland from Marsoft S.A. Be aware of them!...
221.192.199.49 - "Saki Haki"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
IP destination address : 76.227.65.191
Number of attempts ...
221.192.199.49 - "Haki Saki"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
IP destination address : 76.227.65.191
Number of attempts ...
184.173.195.64 - "Hacky SakI"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
IP destination address : 76.227.65.191
Number of attempts ...
8.26.213.253 - ??
????? ???? ????? ?? ?? ????? ?????? ? ? ???????? ?? ??? ??? ???? ???? ?? ?????? ?????? ?? ??????? ??? ?????? ??????? ?? ?????? ?? ?????? ??????? ??? ????? ??????? ?? ?????...
184.173.195.64 - "Rats Nest"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
IP destination address : 76.227.65.191
Number of attempts ...
184.173.195.64 - "Awww Yeah"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
IP destination address : 76.227.65.191
Number of attempts ...
184.173.195.64 - "Hmmm"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
IP destination address : 76.227.65.191
Number of attempts ...
221.192.199.49 - "Rats Nest"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
IP destination address : 76.227.65.191
Number of attempts ...
184.173.195.64 - "Stirring"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
IP destination address : 76.227.65.191
Number of attempts ...
121.10.134.100 - "Stirring"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 121.10.134.100
IP destination address : 76.227.65.191
Number of attempts ...
184.173.195.64 - "China Connection"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
IP destination address : 76.227.65.191
Number of attempts ...
192.168.1.5 - problem with acout
I want to sign injand i cant i dont know whats going on with my acout
can you reply my acount and pasworld to my email :atzalaproduce@gmail.com...
184.173.195.64 - "Continous FlyBys"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
IP destination address : 76.227.65.191
Number of attempts ...
58.53.147.114 - "Rats Nest"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 58.53.147.114
IP destination address : 76.227.65.191
Number of attempts ...
184.173.195.64 - "Again"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
IP destination address : 76.227.65.191
Number of attempts ...
75.126.141.159 - "Again"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 75.126.141.159
IP destination address : 76.227.65.191
Number of attempts ...
184.173.195.64 - "Again"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
Number of attempts : 1
Time at last attempt : 2/25/12 0...
75.126.141.159 - "Possible Connection"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 75.126.141.159
IP destination address : 76.227.65.191
Number of attempts ...
184.173.195.64 - "Port Scanning"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
IP destination address : 76.227.65.191
Number of attempts ...
182.113.173.145 - "In League with"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 182.113.173.145
Number of attempts : 3
Time at last attempt : 2/24/12 ...
221.192.199.49 - "ScanMaster"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
Number of attempts : 3
Time at last attempt : 2/24/12 1...
68.37.246.196 - telnet attempt into my pc
telnet into my machine attempt telnet into my machine attempt telnet into my machine attempt telnet into my machine attempt telnet into my machine attempt telnet into my machine attempt ...
221.192.199.49 - "Intruder Alert"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
Number of attempts : 1
Time at last attempt : 2/24/12 1...
221.192.199.49 - "Trying to climb down the Chimney"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
IP destination address : 76.227.65.191
Number of attempts ...
91.226.78.129 - 91.226.78.129
Received an alert that a Russian IP address, 91.226.78.129, was attempting to access my computer. Thankfully it was blocked.
General IP Information
IP: 91.226.78.129
Decimal: 1541557889
Hostname: 9...
58.218.199.147 - Firewall probing
I have several firewalls reporting this IP address probing them on several different ports. Here is a list of some of the ports that this IP address tried access.
8085/tcp
socks/tcp 1080
7212/tcp
81...
221.192.199.49 - "Ass Wipe"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 221.192.199.49
Number of attempts : 87
Time at last attempt : 2/22/12 ...
187.126.121.81 - Many alerts
from multiple IPs
Tue Feb 21 17:04:18 2012
=>Found attack from 187.126.121.81.
Source port is 2335 and destination port is 36649 which use the TCP protocol. ...
58.218.199.87 - 58.218.199.87 firewall alerts
Tue Feb 21 17:02:45 2012
=>Found attack from 58.218.199.87.
Source port is 12200 and destination port is 6515 which use the TCP protocol.
Tue Feb 21 17:08:25 2012
=>Found attack from 58.218...
46.22.239.167 - =>Found attack from 46.22.239.167. Source port is 12049 and destination port is 36649 which use the TCP protocol. Tue Feb 21 17:25:24 2012
will not stop..about every 3 to 4 min
Tue Feb 21 17:15:36 2012
=>Found attack from 46.22.239.167.
Source port is 12049 and destination port is 36649 which use the TCP protocol.
Tue Feb 21 17:2...
65.191.122.40 - HackAttack: [SPI:Illegal connection state attack]
Feb 21 21:49:56 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 65.191.122.40 to 80.220.22.74
Feb 21 21:50:05 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
200.221.136.146 - HackAttack: [SPI:Illegal connection state attack]
Feb 21 14:50:36 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 200.221.136.146 to 80.220.22.74
Feb 21 15:02:05 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
68.68.22.133 - HackAttack: [SPI:Illegal connection state attack]
Feb 21 04:53:53 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.68.22.133 to 80.220.22.74
Feb 21 05:51:40 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
204.93.180.2 - TCP Intrusion from 204.93.180.2
TCP from 204.93.180.2 to local port 80 Denied: Intrusion.Generic.WebApp.DirTravers.exploit
21-02-2012 01:19:33(IST)
caught by kaspersky internet security.
Repeated Directory traverse exploit.
More ...
77.247.177.45 - outgoing attempt by IP 77.247.177.45
I have Malwarebytes running and every morning I receive an alert informing me that it has blocked IP 77.247.177.45, Process Skype.exe. Googled this IP address and it is showing up as from the Netherl...
188.116.55.243 - HackAttack: [TCP SYN Flooding]
Feb 20 00:45:01 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 188.116.55.243:6664 to 80.220.22.74:6664
Feb 20 00:45:01 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 188.116.55.243:666...
95.168.173.155 - 95.168.173.155
OUT GOING ? does this mean spyware is trying to phone home ?
2012/02/19 19:25:53 -0500 PAT- IP-BLOCK 94.100.30.163 (Type: outgoing, Port: 49328, Process: dragon.exe)
2012/02/19 19:25:54 -0500 PAT-...
91.205.41.57 - McAfee Risky connection blocked
I received a risky connection blocked message regarding the IP address 91.205.41.57. This occured during the night while no one was on the computer....
221.192.199.49 - 221.192.199.49
How can we attack this guy and his ISP?
Unless this is State supported hacking we ought to be able to make life difficult for him....
95.180.90.144 - port scanning atac detected
attacks from this ip address detected more than once a day for a while now, please block it if possible, I have eset smart 5 but I want to be sure
...
121.45.143.189 - HackAttack: [SPI:Illegal connection state attack]
Feb 17 22:46:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 121.45.143.189 to 80.220.22.74
Feb 17 22:46:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
Date Time Message
[INFO] Wed Feb 15 10:18:41 2012 Blocked incoming TCP connection request from 86.38.10.105:35151 to 86.*.*.*:23
[INFO] Thu Feb 16 22:42:45 2012 Blocked incoming TCP connection request...
85.17.24.101 - ATACK
THIS IP WOS DETECTED ATACK MY COMPUTER IT ATACK MY COMPUTER I WANT BE SURE THAT IP DONT ATACK AGAIN MY COMPUTER NOT NOW AND NOT IN THE FUTURE I HOPE TO REZOLVE YOU THIS SITUATION...
58.218.199.147 - Stay to hell out of my computer
My computer tell me this ip keeps trying to break in.Shut it down or my people will destroy that system.this is the only and final warning....
58.218.199.227 - Port Scan Detected
Multiple port scans which were blocked from this remote IP address. These are happening many times daily over a couple of months. adding words just to get past 25....
88.190.227.122 - Trying to connect to servers
This IP is trying to Ssh to our Servers.
*Jun 20 17:30:01.268: %SEC-6-IPACCESSLOGP: list FILTRA-IN denied tcp 88.190.227.122(29553) -> 66.175.xxx.xxx(22), 1 packet
*Jun 20 17:30:08.876: %SEC-6-IP...
184.173.195.64 - "Constant Aggressor"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 184.173.195.64
Number of attempts : 2
Time at last attempt : 2/15/12 0...
208.73.210.29 - Hacking
Keep getting a firewall intrusion report from IPs that come from Oversee.net. Since these firewall intrusions have come up my pc has been slowed down and I am finding more and more malware....
50.22.0.186 - HackAttack: [SPI:Illegal connection state attack]
Feb 15 09:32:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.22.0.186 to 80.220.22.74
Feb 15 09:33:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
218.19.175.252 - Terminal Server initiation attempt
Constant Terminal server session attempts. Firewall detected constant requests for non encrypted Terminal Server session from IP Address 218.19.175.252. The IP has beed reported for port scanning in t...
89.36.160.154 - ICMP flooding attack
I have communicate from firewall with this ip about ICMP flooding attack. What it\'s mean? What to do? Is it danger for my computer if firewall see it?...
109.236.87.119 - Tentative d'intrusion détectée
Tentative d\'intrusion détectée : NULL scan (TCP flag set)
Heure : 08/02/2012 20:49:44
Direction : Entrant
Protocole : tcp
Services : TCP High Ports in
Adresse distante : 1...
85.17.48.106 - HackAttack: [SPI:Illegal connection state attack]
Feb 15 00:09:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 85.17.48.106 to 80.220.22.74
Feb 15 00:09:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
50.115.119.10 - HackAttack: [SPI:Illegal connection state attack]
Feb 5 18:47:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.115.119.10 to 80.220.22.74
Feb 13 19:00:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
218.75.49.242 - "Slammer" worm to compromise a Microsoft SQL Server.
Block external access to the MS SQL services on port 1433 and 1434 if possible.
Patches from Microsoft are available that fix this vulnerability. The patches are available from www.microsoft.com/tech...
94.78.137.200 - Network Intrusion
I just received a network intrusion from ip addres: 94.78.137.200.
It\'s addrees is the following:
STREAM COMMUNICATIONS SpóÅka z o.o.
Al. 29 Listopada 130
31-406KrakÃ&sup...
188.116.4.167 - HackAttack: [TCP SYN Flooding]
Feb 13 10:48:23 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 188.116.4.167:6661 to 80.220.22.74:6661
Feb 13 10:48:23 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 188.116.4.167:6664 ...
50.115.119.10 - HackAttack: [SPI:Illegal connection state attack]
Feb 5 18:47:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.115.119.10 to 80.220.22.74
Feb 13 19:00:15 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
219.71.67.218 - HackAttack: [SPI:Illegal connection state attack]
Feb 13 02:44:59 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 219.71.67.218 to 80.220.22.74
Feb 13 02:45:02 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
83.133.119.155 - german krauts keep trying to hack my pc
83.133.119.155
leads to some asshole kraut in germany in a shack somewhere trying to hack my pc with a dialup connection. when will these losers realize that they suck and to stop trying to hack into ...
76.16.103.199 - HackAttack: [SPI:Illegal connection state attack]
Feb 12 02:15:00 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 76.16.103.199 to 80.220.22.74
Feb 12 02:15:11 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
108.163.192.227 - HackAttack: [SPI:Illegal connection state attack]
Jan 6 00:23:05 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 108.163.192.227 to 80.220.22.74
Jan 6 19:05:39 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
212.117.177.110 - try to contact
Firewall Alert:
try to contact with one application lsass.exe on my system (Port: 500). I had any connection with this server bevore.
Warning! Attantion on this server, Fraud possible....
188.116.55.243 - HackAttack: [TCP SYN Flooding]
Feb 10 02:47:45 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 188.116.55.243:6665 to 80.220.22.74:6665
Feb 10 02:47:45 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 188.116.55.243:666...
50.115.119.14 - HackAttack: [SPI:Illegal connection state attack]
Feb 9 20:39:28 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.115.119.14 to 80.220.22.74
Feb 10 02:22:00 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
68.168.119.10 - HackAttack: [SPI:Illegal connection state attack]
Feb 1 22:35:36 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.168.119.10 to 80.220.22.74
Feb 9 02:05:59 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Feb 8 05:10:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Feb 9 06:22:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
76.10.222.26 - "Multiple Hits"
First time seeing this IP address, hope he\'s not planning to stay long.
Security alert type : IP Subnet Broadcast Amplification
IP source address : 76.10.222.26
Number of...
188.227.184.184 - HackAttack: [SPI:Illegal connection state attack]
Jan 11 22:34:07 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 188.227.184.184 to 80.220.22.74
Jan 29 01:42:38 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
180.76.5.54 - 180.76.5.0 / 255.255.255.0
This IP range keeps trying to guess a session for an installer on my server each 30 seconds, eventually switching IPs.
Here\'s a list of the main IPs with the count of attempts in the last few days:...
46.105.124.26 - TCP SYN-FLOOD
2012 Feb 6 11:41:13 [Firewall Floriana] [kernel] SYN-FLOOD IN=WAN OUT=LAN SRC=46.105.124.26 DST=78.133.124.103 PROTO=TCP SPT=6665 DPT=6665
2012 Feb 6 11:41:13 [Firewall Floriana] [kernel] SYN-FLO...
10.80.18.75 - Getting hammered
Constanlty getting hammered 24/7 by this IP on different ports. Maybe part of a botnet? UDP ...
8.33.7.45 - sniffer
This finok is pocking around TCP:S port 65533
Leave people alone, you\'ll live longer. ...
124.239.195.131 - Hacker
Cut China off the internet!
ET DROP Dshield Block Listed Source
GPL SQL Slammer Worm propagation attempt
...
60.190.222.143 - Hacker
Cut china off the internet!
Fire wall allert, Blocked TCP
ET CIARMY Collective Intelligence Security Poor Reputation IP (TCP) ...
199.254.56.254 - Hacker
Known delinquent
Blocking TCP connection
ET CIARMY Collective Intelligence Security Poor Reputation IP (UDP)
...
46.105.124.26 - HackAttack: [TCP SYN Flooding]
Feb 7 13:51:11 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 46.105.124.26:6662 to 80.220.22.74:6662
Feb 7 13:51:11 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 46.105.124.26:6666 ...
94.75.215.26 - tcp nullport
Report firewall. IDS proto parser : tcp null port (1 of 1) : 94.75.215.26 81.228.154.22 0040 TCP 0->59047 [..AR..] seq 0 ack 1218583930 win 0...
46.105.124.26 - firewall attack
why firewall attack.why firewall attack.why firewall attack.why firwhy firewall attack.ewall attack.why firewall attack.why firewall attwhy firewall attack.ackwhy firewall attack..why firewall attack....
99.250.64.62 - HackAttack: [SPI:Illegal connection state attack]
Feb 7 08:48:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 99.250.64.62 to 80.220.22.74
Feb 7 08:57:17 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
99.250.64.62 - HackAttack: [SPI:Illegal connection state attack]
Feb 7 07:56:55 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 99.250.64.62 to 80.220.22.74
Feb 7 07:56:58 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
99.250.64.62 - HackAttack: [SPI:Illegal connection state attack]
Feb 7 03:14:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 99.250.64.62 to 80.220.22.74
Feb 7 03:14:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
70.83.33.13 - HackAttack: [SPI:Illegal connection state attack]
Feb 7 02:55:21 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 70.83.33.13 to 80.220.22.74
Feb 7 02:55:21 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
99.250.64.62 - HackAttack: [SPI:Illegal connection state attack]
Feb 7 02:53:56 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 99.250.64.62 to 80.220.22.74
Feb 7 02:54:29 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
98.221.73.207 - HackAttack: [SPI:Illegal connection state attack]
Feb 6 16:29:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 98.221.73.207 to 80.220.22.74
Feb 6 16:29:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
61.235.46.146 - Network Attack
Kaspersky reports Intrusion.Win.MSSQL.worm.Helkern. That\'s one of attack today. Next one was from 124.239.195.131. What\'s goin\' on? What\'s profit from this attack? Who else had this attack?...
8.33.7.45 - Same Clown Different IP Address
Had problems with this Fool before, He\'s back and up to his old tricks. The change of IP address is not the least bit convincing. His local has not changed any more than his foolhardiness. Keeping...
Kaspersky has denied an network intrusion attack from this IP address. Intrusion.Win.MSSQL.worm.Helkern UDP from 124.239.195.131 to local port 1434
IP Address: 124.239.195.131
IP Address Country: ...
124.239.195.131 - Repeated Network Attack On My PC Over Several Days
IP Address: 124.239.195.131
IP Address Country: China (CN)
IP Address Region: 22 Beijing
IP Address City: Beijing
IP Postal Code
IP Address Area Code 0
IP Metro Code 0
IP Address Latitude: 3...
98.221.73.207 - HackAttack: [SPI:Illegal connection state attack]
Feb 6 13:13:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 98.221.73.207 to 80.220.22.74
Feb 6 13:13:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
175.45.25.51 - Hacking
This IP has been trying to infiltrate my computer for the past 2 weeks! this is getting to be very annoying, the IP 175.45.25.51 please deal with it soon....
218.75.49.242 - Attempt of intrusion
UDP from 218.75.49.242 to local port 1434 Intrusion.Win.MSSQL.worm.Helkern tried to attack my computer 05/02/2012 at 19:19:22 but was stopped by KASPERSKY
The IP-address seems to be from China...
218.75.49.242 - Worm
A dedection by my Computer, comes from China ?:
UDP from 218.75.49.242 to local port 1434 Denied: Intrusion.Win.MSSQL.worm.Helkern 05/02/2012 19:11:55
[Querying whois.apnic.net]
[whois.apnic.net]
% ...
58.218.199.147 - Dangerous scan
Hard scan ,i dont like this,fuck,fuck,fuck,fuck china people.They eat shit.Yelow monkey,eat shit. and lck mi balls.Eat shit,shit shit,shit,fuck,fuck,fuck, each other,yelow monkey.Motherfucker,eat shit...
91.205.41.180 - HackAttack: [SPI:Illegal connection state attack]
Feb 5 04:17:29 HackAttack: [SPI:Illegal connection state attack] TCP packet from [nas0] 91.205.41.180:80 to 80.220.22.74:11561
Feb 5 04:18:08 HackAttack: [SPI:Illegal connection state attack] TCP p...
50.115.119.10 - HackAttack: [SPI:Illegal connection state attack]
Feb 5 03:06:43 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.115.119.10 to 80.220.22.74
Feb 5 03:45:30 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
68.67.159.206 - risky connection
Caught numerous times by McAfee. Arin shows this IP address as originating in New York, yet this site shows the address in Anaheim, Ca??? Makes me very suspicious....
193.107.16.156 - 193.107.16.156 Attacking
This IP has been trying to access to my laptop for days.
Started with \"DNS cache poisoning attack\" 10-20 at a time.
Then Malwarebytes started to block this IP address.
Says \"Potentia...
176.65.154.43 - Trojan
2 different trojans try to connect to this IP on several different ports, trojan appears for example as 2 different processes called 0000.exe and 30D.exe under Windows 7, seams to spread fast....
174.138.172.138 - HackAttack: [SPI:Illegal connection state attack]
Feb 2 20:18:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.138.172.138 to 80.220.22.74
Feb 2 22:36:11 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
68.67.159.206 - Outgoing connection blocked by Mcafee
Outgoing connection blocked by Mcafee. This has been happening a few time from my PC. Is there a way to figure out if this is malware, trojan or the likes?...
89.28.85.29 - Malwarebytes Anti-malware
Malwarebytes Anti-malware
17:07:40 computer IP-BLOCK 89.28.85.29 (Type: incoming)
17:07:43 computer IP-BLOCK 89.28.85.29 (Type: incoming)
17:07:49 computer IP-BLOCK 89.28.85.29 (Type: incoming)
17:07...
109.73.78.210 - HackAttack: [SPI:Illegal connection state attack]
Jan 13 01:34:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 109.73.78.210 to 80.220.22.74
Jan 31 16:58:26 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
94.156.248.190 - HackAttack: [SPI:Illegal connection state attack]
Jan 20 02:32:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.156.248.190 to 80.220.22.74
Jan 20 11:28:47 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
121.29.187.225 - Yuan Lee Sculpture Plant
Yuan Lee Sculpture Plant produces a variety of professional Roman Statue Greek Statue marble carvings. Including Western figures, animals, fountains, fireplaces, columns, flower pots Garden ornaments...
109.163.230.114 - MalwareBytes Anti-Malware
MalwareBytes Anti-Malware IP-BLOCK 109.163.230.114 (Type: outgoing)
IP-BLOCK 109.163.230.114 (Type: outgoing)
IP-BLOCK 109.163.230.114 (Type: outgoing)
IP-BLOCK 109.163.230.114 (Type: outgoing)
IP...
62.213.100.140 - MalwareBytes Anti-Malware
MalwareBytes Anti-Malware IP-BLOCK 62.213.100.140 (Type: outgoing)
IP-BLOCK 62.213.100.140 (Type: outgoing)
IP-BLOCK 62.213.100.140 (Type: outgoing)
IP-BLOCK 62.213.100.140 (Type: outgoing)
IP-BLO...
212.117.177.190 - MalwareBytes
MalwareBytes Anti-Malware souspicios IP-BLOCK 212.117.177.190 (Type: outgoing)
IP-BLOCK 212.117.177.190 (Type: outgoing)
IP-BLOCK 212.117.177.190 (Type: outgoing)
IP-BLOCK 212.117.177.190 (Type: o...
61.235.46.146 - Kaspersky reports Intrusion
Detected: Intrusion.Win.MSSQL.worm.Helkern reported attak by kapersky firewall
ilyfy uf ufy uyf u ufuot f uofyo uf uof ou ou fouyf fof f uyyu fou foufy yu fyo u oufy uo fyfo o u fou...
124.239.195.131 - MS SQL Server 2000 Resolution Service Attack
MS SQL Server 2000 Resolution Service Attack
124.239.195.131
happened today Jan 31, at 5:29:47 PM
Application: /match_kernel
I\'m currently located in virginia if that makes a difference.
blocked by m...
173.245.60.117 - Constant hijacking
My antivirus has been blocking this ip address constantly.
It is unknown what it is attempting to do, but it has not stopped trying for over 12 hours now.
I cannot seem to stop the attacks......
80.93.62.130 - malware
malware, trying to send to a specific port. Looked at different wallpapers, during this I firewall alert came up stating that 80.93.62.130 was trying to connect. spam spam spam....
124.239.195.131 - Attack
Fuck chineses. Shit people, shit culture, shit products...you are all shit! Why you do not attack your own idiot brothers... Why you have to invade our computers, countries, etc...Blood hell!...
188.72.201.33 - 188.72.201.33.80
My friend\'s Nod 32 Firewall blocked this IP: 188.72.201.33.80 with the following address: blood4.cu.cc/in.cgi?2
Was visiting botanoo.com website.
After that, the site come partly, and permanently una...
58.218.199.147 - attack on port
firewall keeps saying attack on port from ip 58.218.199.147 many times ten or more in 5 minutes , every time i turn on pc it says attack nutralized from this ip address...
89.28.94.71 - Incoming UDP firewall alert
we are receiving a continue firewall and malware UDP alert blocked by our malware blockers. This is going on since many weeks and months...
208.115.218.154 - HackAttack: [SPI:Illegal connection state attack]
Jan 29 18:51:21 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 208.115.218.154 to 80.220.22.74
Jan 29 20:42:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
200.162.212.245 - HackAttack: [SPI:Illegal connection state attack]
Jan 29 15:21:14 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 200.162.212.245 to 80.220.22.74
Jan 29 15:21:17 HackAttack: [SPI:Illegal connection state attack] ICMP packer...
204.12.247.53 - Intrusion attempts by 204.12.247.53
Multiple intrusion attempts from this IP address, blocked by Norton. This is Malicious Toolkit Software. Owner is Alistair Meney of Kansas City. Get a Life, you Subhuman!...
68.173.138.115 - HackAttack: [SPI:Illegal connection state attack]
Jan 29 00:31:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.173.138.115 to 80.220.22.74
Jan 29 00:31:20 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
75.131.113.145 - HackAttack: [SPI:Illegal connection state attack]
Jan 28 22:53:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 75.131.113.145 to 80.220.22.74
Jan 28 22:53:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
124.239.195.131 - attack UDP
This attack is a Intrusion.Win.MSSQL.worm.Helkern UDP from 124.239.195.131 to local port 1434, at 29/01/2012, 08:19 AM.
Kaspersky stop this attack. This is the first attack (when i use for the first m...
86.107.193.212 - ICMO Flood Atack
Nimic de spus, is obisnuit cu floodoorile de pe servere ca asta. Dar nu ar trebui sa fie asa. Ce bine ca am un antivitus bun....
41.200.142.109 - HackAttack: [SPI:Illegal connection state attack]
Jan 26 21:47:50 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 41.200.142.109 to 80.220.22.74
Jan 26 21:47:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
206.161.121.4 - Malwarebytes alert
Malwarebytes continues popping up this notification. FYI I just cleaned my pc of a really annoying trojan that hid all my files/folders and faked hard drive corruption. This is the MWB notification:
...
193.107.17.86 - McAfee Risky Connection attempt
Received alerts that this IP and another within the adjacent subnet tried to connect via Chrome and SYSTEM. IP lookup seemed to imply links to Russian hosts....
221.192.199.46 - China port probing
I have to reformat all the time...my computer gets taken over by someone in China. I\'m not computer smart but , if I type anything even close to the word China..my firewall gets probed...
58.218.199.147 - 58.218.199.147
I have noticed a few times today this IP trying to connect to my computer. what should I do? can I stop him some how? ...
124.239.195.131 - Network attack
2nd Time this IP adress attacked me, firewall reports possible ip-spoofing.
Rapport: intrusion.win.mssql.worm.helkern
Would be nice to see him taken out of action before he harms anyones belongings....
68.67.159.206 - Attempted risky connection
IP Address: 68.67.159.206
IP Address Country: United States (US)
IP Address Region: CA California
IP Address City: Anaheim
IP Postal Code
IP Address Area Code 714
IP Metro Code 803
IP Addres...
61.235.46.146 - VIRUS SQL Slammer Activity, SID: 1870, Priority: Medium
lert Intrusion Prevention IPS Prevention Alert: VIRUS SQL Slammer Activity, SID: 1870, Priority: Medium 61.235.46.146, 4433, lert Intrusion Prevention IPS Prevention Alert: VIRUS SQL Slammer Activity,...
82.116.76.146 - 82.116.76.146
Please log this as a complaint against the owner of the ip. Multiple user name login attempts were loggedfrom this ip address especially RDP ...
188.122.95.81 - HackAttack: [SPI:Illegal connection state attack]
Jan 22 15:14:39 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 188.122.95.81 to 80.220.22.74
Jan 24 23:52:41 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
61.235.46.146 - Kaspersky detected network attack
I keep getting Network attack reports from KAV av from this ip http://61.235.46.146/
Please let me know what is going on and shut it down somehow...
129.82.138.38 - ICMP Packet Blocked by firewall
I have for a long time, recieved ICMP Packet\'s on Port:42193
It could be nice if it could be stopped.
I have no interrest of getting on known trafik at my Network.
An spammer should not be allowd on ...
204.12.247.53 - Intrusion Prevention
[SID: 24089] Web Attack: Malicious Toolkit Website 9 detected.
Traffic has been blocked from this application: C:\\Program Files\\Internet Explorer\\iexplore.exe
Symantec detected attempted intrusion...
124.239.195.131 - 124.239.195.131 tried to intrude into my computer
The ip address124.239.195.131 tried to intrude into my computer, but was blocked by my antivirus software. please block their network.
Details Are : Denied: Intrusion.Win.MSSQL.worm.Helkern UDP from ...
68.168.119.10 - HackAttack: [SPI:Illegal connection state attack]
Jan 13 11:19:58 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.168.119.10 to 80.220.22.74
Jan 17 06:30:46 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
178.74.94.245 - Blocked incoming TCP connection request from 178.74.94.245
[INFO] Sun Jan 22 12:05:06 2012 Blocked incoming TCP connection request from 178.74.94.245:4916 to 109.173.114.61:37178
[INFO] Sun Jan 22 11:50:20 2012 Blocked incoming TCP connection request from 178...
94.142.134.238 - Failed Login Attempts
I have Blocked this IP Address because of the following: This IP Address made 16 Failed Login Attempts to my website\'s Admin section. obvious attempt to hack a website....
94.100.30.164 - outgoing
Malware bytes blocks this as outgoing. What I want to know is what and where the item that is in my computer that is sending this out. Any ideas?...
208.83.20.130 - "Persistent Attacks"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 208.83.20.130
IP destination address : 76.227.65.191
Number of attempts ...
58.218.199.147 - 58.218.199.147
58.218.199.147 has been poping up every day on my firewall. Fuck off you sick fucks. Really go screw yourself. Im tired of dealing with you people....
204.12.247.53 - Cadegory 9 Web Hazard
Was playing a kids game. Norton360 gave me an alert. It said high alert and very dangerous. I asked an ask website and it said it was the NSA, but I\'m not buying that :/...
64.40.8.200 - Firewall Alert server me
2012-01-20 05:10:20 DROP UDP 64.40.8.200 109.230.244.125 20000 61022 128 - - - - - - - RECEIVE
2012-01-20 05:10:20 DROP UDP 64.40.8.200 109.230.244.125 20000 61024 128 - - - - - - - RECEIVE
2012-01-20...
95.168.173.155 - Malware antivirus blocked it
Malware anti virus said it blocked it and it wa soutgoing, what ever this mean?
I keeptyping as I need 25 words but I don\'t have anything else to say ...
210.118.80.41 - intrusion
UDP from 218.75.49.242 to local port 1434 Denied: Intrusion.Win.MSSQL.worm.Helkern 20/01/2012 05:36:57
UDP from 218.75.49.242 to local port 1434 Denied: Intrusion.Win.MSSQL.worm.Helkern 17/01/2012 1...
204.12.247.53 - intrusion from this ip address 204.12.247.53
i am receiving multiple intrusion attack from this address and ok5015 .com reported by norton i think there trying to hack in to my comp but the can haha liv my shit alone bitches ...
58.218.199.147 - Network attack.
I believe this is the second time this person has tried to Network attack me. I don\'t have any private documents or anything of the source but my privacy is being invaded....
125.45.109.166 - access
Well it looks like they are back at it. I get several alerts a day they are trying to access my computer. Norton did not stop but the paid version of Malwarebytes did. Why the 25 word thing ?...
222.189.238.121 - access
This is another ip address my firewall blocked. There are several from Beijing. What is up with this? i don\'t need 25 words people ok!...
208.83.20.130 - access
this ip is trying to get into my computer everyday! Who are they and can they be shut down?This is to get 25 words jeez....
69.16.190.26 - HackAttack: [SPI:Illegal connection state attack]
Jan 18 03:33:53 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 69.16.190.26 to 80.220.22.74
Jan 18 21:58:19 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
46.105.124.26 - HackAttack: [TCP SYN Flooding]
Jan 18 17:21:04 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 46.105.124.26:6666 to 80.220.22.74:6666
Jan 18 17:21:04 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 46.105.124.26:6665 ...
61.235.46.146 - Network Attack
18/01/2012 14:43:06. Detected:Intrusion.Win.MSSQL.worm.Helkern UDP from 61.235.46.146 to local port 1434. Attack blocked by Kaspersky. To me it is terrible. What to me to do? Help me!
...
140.192.249.203 - something new?
From my router log: Found attack from from this address. 140.192.249.203 Use the ICMP protocol. Have a couple more from different universities popping up all of the sudden....
141.212.113.178 - something new?
From my router log: Found attack from from this address. 141.212.113.178 Use the ICMP protocol. Have a couple more from different universities popping up all of the sudden....
192.42.83.250 - something new??
From my router log: Found attack from from this address. 192.42.83.250. Use the ICMP protocol. Have a couple more from different universities popping up all of the sudden....
192.42.83.251 - Something new??
Found attack from from this address. 192.42.83.251 Use the ICMP protocol. Have a couple more from different universities popping up all of the sudden....
208.83.20.130 - Repetitive blocked trials to acces my computer
This IP has been trying to get into my computer with astounding frequency during this weed. This is today\'s Malwarebytes log:
2012/01/17 10:06:47 +0100 IP-BLOCK 208.83.20.130 (Type: incoming)
2012/0...
83.133.124.245 - Malware Bytes blocking 83.133.124.245
My commuter is trying to communicate to 83.133.124.245 when browser is open.
This attempt is blocked by Malware Bytes. I suspect that this is a Trojan....
86.107.193.212 - Citeste!
Ai grija cu ii dai flood, bucuresteanule, internetul e mare, gaseste pe altcineva, stai cumva pe strada doamnei pe la jupiter groups ori ceva de genu! iti trimit o surpriza, te gasesc stai linistit!...
175.45.25.83 - Alert
my Firewall alerted of the following -:
Somebody is scanning your computer.
Your computer\'s TCP ports
have been scanned from 175.45.25.83.
I am geting this attack on my virus software
Please block...
212.113.36.83 - cant open my yahoo and many sites
Cannot access microsoft.com , linkedin, yahoo, way2sms . Keeps opening a page full of ads. Malwarebytes keeps showing this ip: 212.113.36.83 when i try to connect. ...
83.133.122.116 - Malware bytes blocks this - I did not set to go here
Malware bytes blocks this as it attempts an outgoing access to ip address.
How do I get rid of this and clear my PC? ...
95.169.186.93 - malware - trying to access website but is blocked
Malware bytes blocks this - cannot get off my machine. How do I get this
to stop? My machine should not be trying to access a Russian website.
...
218.75.49.242 - Intrusion Prevention
Alert Intrusion Prevention IPS Prevention Alert: VIRUS SQL Slammer Activity, SID: 1870, Priority: Medium 218.75.49.242, 40076, X1 ***.***.*.*, 1434, X* Alert Intrusion Prevention IPS Prevention Alert...
31.128.209.139 - Blocked incoming TCP connection request from 31.128.209.139
[INFO] Mon Jan 16 00:29:16 2012 Blocked incoming TCP connection request from 31.128.209.139:4062 to 109.173.114.61:32461
[INFO] Mon Jan 16 00:29:10 2012 Blocked incoming TCP connection request from 31...
208.83.20.130 - "Persistent Alerts"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 208.83.20.130
IP destination address : 76.227.65.191
Number of attempts ...
117.228.56.204 - detecting port scanning attack
could u take care of my pc by hiding my ip as some one trying to intrude into my pc plx kindly do me a favour...
208.83.20.130 - Repeated malicious incoming attempts
208.83.20.130 numerous attempts of a malicious nature logged as attempted intrusions to access my computer. Will someone ably do something about this conduct?...
208.83.20.130 - "Constant Aggresion"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 208.83.20.130
IP destination address : 76.227.65.191
Number of attempts ...
208.83.20.130 - 208.83.20.130
208.83.20.130 has been trying to access my computer multiple times. Does anyone know who they are they and why are they trying to get in my computer?? ...
208.83.20.130 - "Unkown Attack"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 208.83.20.130
IP destination address : 76.227.65.191
Number of attempts ...
111.22.170.178 - Intrusion Prevention
01/14/2012 06:00:21.272 Alert Intrusion Prevention IPS Prevention Alert: VIRUS SQL Slammer Activity, SID: 1870, Priority: Medium 111.22.170.178, 4395, X1 ***.***.*.*, 1434, X3 01/14/2012 06:00:21.272...
95.169.186.166 - Chrome.exe
Malwarebytes protection is showing chrome.exe (Google Chrome web browser) repeatedly trying to connect to this website through progressive port numbers, in order. Calls are being blocked by Malwareby...
219.94.195.21 - Accessed email account
This site accessed my gmail acct. at 12:16 am CST on 01/13/2012. Alerted by host. Purpose unknown. No previous attempts from this server. Changed password....
82.73.85.241 - HackAttack: [SPI:Illegal connection state attack]
Jan 12 23:15:41 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 82.73.85.241 to 80.220.22.74
Jan 12 23:15:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
58.218.199.227 - Attempted hacking.
Attempted connections on multiple service ports. Mostly probing, but obviously trying to find vulnerable services.
IRDMI (tcp/8000)
RADAN-HTTP (tcp/8088)
HTTP-ALT (tcp/8080)
(tcp/6588)
(tcp/8090)
(tc...
193.106.172.172 - 193.106.172.172
Malwarebytes is currently blocking this site. It belongs to warez-bb.org and probably they have received a copyright complaint. I would suggest adding it to your ignore list. I would rather control my...
195.216.243.184 - malware bytes log alert
Same problem as above person:
this site keeps showing up in my malware bytes log. The whole day my pc has been trying to send info to this ip. I suspect keyloggers
IP-BLOCK 195.216.243.151 (Type: ou...
62.45.191.252 - Alert from Malwarebytes for IP 62.45.191.252
Alert from Malwarebytes on jan 12th for IP 62.45.191.252 Skype.exe on port 2968, outgoing connection. Also reported other application outgoing activity on different ports. ...
195.216.243.42 - keyloggers ?
Alert from Malware bytes for jan 11th kept happening throughout the day, could this be an attempt at keylogging ?
IP-BLOCK 195.216.243.42 (Type: outgoing, Port: 50199, Process: firefox.exe)...
193.109.247.46 - keyloggers ?
log from Malware bites, received 6 times in the last 2 hours. Could this be an attempt at keylogging ?
IP-BLOCK 193.109.247.46 (Type: outgoing, Port: 59321, Process: firefox.exe)
...
61.235.46.146 - hacking attent
Intrusion from IP 61.235.46.146(3875) at 12-01-2012 at 11.31 london time.
Norton internet security blocked the attent on MS SQL Stack BO at door ms-sql-m(1434)...
[INFO] Wed Jan 11 02:20:48 2012 Blocked incoming TCP connection request from 95.111.158.52:58648 to 109.173.114.61:32461
[INFO] Wed Jan 11 02:20:43 2012 Blocked incoming UDP packet from 95.111.158.52:...
195.216.243.44 - keyloggers ?
this site keeps showing up in my malware bytes log. The whole day my pc has been trying to send info to this ip. I suspect keyloggers
IP-BLOCK 195.216.243.44 (Type: outgoing, Port: 50741, Process: fi...
195.216.243.151 - keyloggers ?
this site keeps showing up in my malware bytes log. The whole day my pc has been trying to send info to this ip. I suspect keyloggers
IP-BLOCK 195.216.243.151 (Type: outgoing, Port: 51142, Process: f...
this site keeps showing up in my malware bytes log. The whole day my pc has been trying to send info to this ip. I suspect keyloggers
IP-BLOCK 195.216.243.151 (Type: outgoing, Port: 51142, Process: f...
75.138.117.138 - Detected unexpected data in protocol
my Smart security 5 eset Detected unexpected data in protocol sevral times from that ip whats that is it dangerous pls can u help what sould i do
...
68.168.119.10 - HackAttack: [SPI:Illegal connection state attack]
Jan 3 09:08:36 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.168.119.10 to 80.220.22.74
Jan 4 14:55:34 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
174.127.92.233 - HackAttack: [SPI:Illegal connection state attack]
Jan 9 02:52:00 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 174.127.92.233 to 80.220.22.74
Jan 9 12:01:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
108.60.144.58 - Gmail accessed by Talktone
Google Gmail warned me that my account had been compromised by this ip address by 108.60.144.62, 108.60.144.58, 108.60.144.59. I found that on another site that the IP/S were linked to Talktone serv...
199.254.56.254 - Blocked incoming TCP packet
[INFO] Mon Jan 09 09:45:01 2012 Blocked incoming TCP packet from 199.254.56.254:53 to 109.173.114.61:51923 as SYN:ACK received but there is no active connection
[INFO] Mon Jan 09 09:09:41 2012 Blocked...
69.4.230.26 - Attack on my Youtube account
I was on my Youtube account and then for a brief second Nortan said.
Attack by iklunix.net (69.4.230.26.80)
This person has done it most then just once.
I even think that this guy has been hacking ...
71.249.189.128 - The following critical firewall event was detected
Message meets Alert condition
The following critical firewall event was detected: Critical Event.
2012-01-08 17:23:44 device_id=FGT60B3908668135 log_id=0104032002 type=event subtype=admin pri=alert vd...
74.117.56.131 - Tried to gain acces to our router/network harddisk
Someone behind this IP-address tried to gain access (without our permissions) to our router and network allocated storagedevice.
After 3 attempts the IP was blocked. ...
41.105.115.114 - HackAttack: [SPI:Illegal connection state attack]
Jan 6 22:14:43 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 41.105.115.114 to 80.220.22.74
Jan 6 22:14:44 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
69.4.230.26 - Attacked me!
This IP address attempted to hack my computer, but it was blocked by my anti-virus software. They may have also planted numerous Trojans (at least 3)...
Malware bytes siftware is blocking outgoing message... i dont know them.. i did not send anything..
it happens when computer comes out of sleep mode or after start up...
193.106.172.172 - Added itself to my Malware Bytes ignore list
No idea what for or what it does, It added itself to my Malware Bytes ignore list within the last 12 hours - while I was sleeping....
206.161.121.5 - ip address
We had a virus on our pc and were working on cleaning it up. We installed malwarebytes and it kept popping up a message saying our pc was trying to send information to this ip address. I did a searc...
61.235.46.146 - UDP from 61.235.46.146 to local port 1434 Denied: Intrusion.Win.MSSQL.worm.Helkern 1/5/2012 7:43:52 PM
I have received this message from Kaspersky Internet Security 2012 from the same IP address more than once (at least 3 times) in the the last 24 hours....
182.148.111.184 - Danger
It keeps attacking all the way...I\'m afraid he is hacking into my system...what can I do to protect my self from it? I wish I have such an answer otherwise I will stop chatting in QQ......
61.235.46.146 - Kaspersky reports Intrusion.Win.MSSQL.worm.Helkern
2012-01-05 04:00:46
UDP from 61.235.46.146 local port 1434
Intrusion.Win.MSSQL.worm.Helkern
Just block it alreddy.I\'m getting pist off right now. How hard can it be? Is there enything else you want...
31.128.203.86 - Persistent hacking attempts on port 32461
Persistent hacking attempts on port 32461.
Thu Jan 05 04:07:18 2012 Blocked incoming TCP connection request from 31.128.203.86:4414 to 109.173.114.61:32461
Thu Jan 05 04:07:12 2012 Blocked incoming T...
206.161.121.4 - phishing attacks
Firewall blocks but bogs down computer. Not sure what they are doing but they are causing all kinds of issues. Stop these people now. Please....
58.218.199.147 - Attack
This happens everyday and is a real pain something needs to be done about them so that this is stopped and you do not have to continue dealing with the attacks...
80.238.233.198 - HackAttack: [SPI:Illegal connection state attack]
Jan 4 10:44:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 80.238.233.198 to 80.220.22.74
Jan 4 10:44:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
124.239.195.131 - Notice from Kaspersky that worm attempted from this IP address
Attempting a work from this IP address but said it could be spoofed..same message as given below on 11/15/2011 by another reporter...Helkern UDP to local port 1434 etc...
31.128.200.138 - Frequent attacks on port 32461
Frequent attacks on port 32461. In the log router periodically writes:
Blocked incoming TCP connection request from 31.128.200.138:3427 to My router IP:32461
Blocked incoming TCP connection request fr...
77.74.36.116 - internet attack
I am receiving a continuous warning from my internet monotoring software about an attack from the address 77.74.36.116. Please stop this attack or we will take an official position....
69.4.230.26 - Web Attack
For a week now I\'ve been getting alerts that my computer is being attacked with malicious toolkit website 9 from this IP address. I\'m not sure if they\'ve succeeded in hacking my computer or not, bu...
220.181.125.44 - Blacklist IP Address
We are getting hit hard by an IP address out of China 220.181.125.44
They are constantly trying to hack into our server and are attempting to enter on every path possible.
Can you please blacklist t...
69.168.140.218 - HackAttack: [SPI:Illegal connection state attack]
Jan 2 22:34:39 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 69.168.140.218 to 80.220.22.74
Jan 2 22:34:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
50.23.212.96 - HackAttack: [SPI:Illegal connection state attack]
Jan 1 04:22:55 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 50.23.212.96 to 80.220.22.74
Jan 1 16:31:47 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
26.134.134.21 - attack of some sort
A program is trying to exploit Windows security holes!
Passwords and sensitive data may be stolen!
Attack from: 26.134.134.21 port 26392
Attacked port: 7783
Threat: Email-Worm.VBS.Peach
...
69.4.230.26 - Access Processing data (Denied)
Recent attempts have been happening a lot recently. Didn\'t download anything and other attacks say it\'s been from this address. This leads me to believe they have tried to hack my computer but faile...
192.168.1.100 - Attempted to connect to my computer somehow
See firewall alert:
Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Category
12/31/2011 11:26 AM,Info,\"Protecting your ...
69.4.230.26 - Attacks
I keep getting notices from my Norton Internet Security about this IP attacking my PC repeatedly. It states Web Attack: Malicious Toolkit Website 9, and attacking computer as crystmassoft3.net (69.4.2...
124.239.195.131 - Alert
12/31/2011 14:08:44.512 Alert Intrusion Prevention IPS Prevention Alert: VIRUS SQL Slammer Activity, SID: 1870, Priority: Medium 124.239.195.131, 3177, X1 **.***.*.* 1434, X312/31/2011 14:08:44.512 Al...
69.4.230.26 - Norton: Web Attack
I keep getting notices from my Norton Internet Security about this IP attacking my PC repeatedly. It states Web Attack: Malicious Toolkit Website 9, and attacking computer as crystmassoft3.net (69.4.2...
68.168.119.10 - HackAttack: [SPI:Illegal connection state attack]
Dec 27 18:05:50 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.168.119.10 to 80.220.22.74
Dec 30 17:58:50 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
66.35.46.195 - unauthorized connects
.195 through .199, multiple port connects reported active this AM, including an FTP port. Am I correct in that the ISP FORTRUST hosts this site?...
91.202.61.170 - "Back Again"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 91.202.61.170
Number of attempts : 15
Time at last attempt : 12/30/11 ...
58.218.199.227 - Continuous alerts
Alert Report from router:
kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=58.218.199.227 DST=123.243.136.217 LEN=40 TOS=0x00 PREC=0x00 TTL=113 ID=256 DF PROTO=TCP SPT=12200 DPT=9090 WINDOW=8192...
221.194.46.176 - Alert
Report from router:
kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=221.194.46.176 DST=123.243.136.217 LEN=40 TOS=0x00 PREC=0x00 TTL=108 ID=256 DF PROTO=TCP SPT=12200 DPT=6588 WINDOW=8192 RES=...
94.45.91.179 - Frequent attacks from the address 94.45.91.179 on port 32461
Frequent attacks from the address 94.45.91.179 on port 32461. Attack the port with an interval of 30-40 seconds.
Firewall: Blocked incoming TCP connection request from 94.45.91.179:1110 to My router I...
69.31.121.130 - HackAttack: [SPI:Illegal connection state attack]
Dec 28 14:18:33 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 69.31.121.130 to 80.220.22.74
Dec 29 05:28:11 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
86.122.87.165 - Unauthorized Remote Administration
I wish to report an internet address that is constantly accessing my router since the beginning of December. The internet address is 86.122.87.165 that is linked to michael.starhost.ro. They are...
95.133.83.197 - Attempted hack of network
Ukraine IP has been attacking our network. the IP has attempted to penetrate our server numerous times in one day using name \"veritas\". the attacks are being blocked by the firewall. ...
76.125.124.158 - http://www.backupduty.com/register
Spamming my computer. Every time I open my computer it appears on the lower right nad corner. I have no use for it at all...
221.194.46.176 - Firewall Alarm
\"** Unauthorized HTTP Access ** <IP/TCP> 221.194.46.176:12200 ->> My_IP:8000\"
I found this message very often recently in the log file of my Router. I do not know the meaning ...
61.235.46.146 - I'm see reports on my firewall that 61.235.46.146 is attacking with DoS MS-SQL Slammer Worm.
I\'m see reports on my firewall that 61.235.46.146 is attacking with DoS MS-SQL Slammer Worm. I\'m see reports on my firewall that 61.235.46.146 is attacking with DoS MS-SQL Slammer Worm....
61.235.46.146 - Intrusion.Win.MSSQL.worm.Helkern
26.12.2011 17:23:35 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.235.46.146 to local port 1434 Absent Attack blocked by Kaspersky Attack blocked by Kaspersky Attack blocked by Kaspersky ...
24.125.160.148 - HackAttack: [SPI:Illegal connection state attack]
Dec 25 15:52:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.125.160.148 to 80.220.22.74
Dec 25 15:52:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
75.82.165.133 - HackAttack: [SPI:Illegal connection state attack]
Dec 25 13:32:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 75.82.165.133 to 80.220.22.74
Dec 25 13:32:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
92.126.66.65 - Attack on the port
Attack on the port:
[INFO] Mon Dec 26 02:56:28 2011 Blocked incoming TCP connection request from 92.126.66.65:50208 to My router IP:32461
[INFO] Mon Dec 26 02:56:22 2011 Blocked incoming UDP packet fr...
61.235.46.146 - Not Authorized Intrussion
A user from using this IP was trying to hack into our Network. This has been registred by our system as a consistent and constant attack. ...
75.82.165.133 - HackAttack: [SPI:Illegal connection state attack]
Dec 25 10:31:08 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 75.82.165.133 to 80.220.22.74
Dec 25 10:31:11 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
75.82.165.133 - HackAttack: [SPI:Illegal connection state attack]
Dec 25 05:52:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 75.82.165.133 to 80.220.22.74
Dec 25 05:52:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
68.168.119.10 - HackAttack: [SPI:Illegal connection state attack]
Dec 23 17:59:18 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.168.119.10 to 80.220.22.74
Dec 24 22:57:38 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
209.18.47.61 - tried to connect
just adding to the report on this ip. my zone alarm keeps hitting on it once in a while jn;awioghgh3oighhjpjfpijgjgjdjg[jagj9ugoptjgpug9rugjrpo...
69.209.73.13 - attacks
100 attacks tried but blocked with wp firewall. This is not the only time someone has tried to attack my site and was blocked. Almost every day this happens. Not from the same ip though....
46.249.57.79 - HackAttack: [SPI:Illegal connection state attack]
Dec 22 08:39:23 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 46.249.57.79 to 80.220.22.74
Dec 22 14:25:28 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
109.235.55.11 - Torrent Tracker IP and port
This is a pirate bay \\ torrentbay tracker ip and port
http://reverseinternet.com/backlinks/domainlinks/torrentbay.to
Your BT client is probably what is connected to it.
I saw it blocked on PeerBlo...
64.94.88.20 - ping every day to my router
ping every day to one of my router.
ping every day to one of my router.
ping every day to one of my router.
ping every day to one of my router....
58.218.199.227 - 58.218.199.277
For two days this IP has been trying to crack into my system. Home PC ... My Norton Firewall is blocking it and reporting on it....
201.66.149.238 - HackAttack: [SPI:Illegal connection state attack]
Dec 19 20:39:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 201.66.149.238 to 80.220.22.74
Dec 19 20:39:38 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
Computer was infected with malware (Windows XP Pro Antivirus 2012). After running malwarebytes to clean the computer. I was unable to run anything on my computer and Symantec kept blocking communica...
209.66.64.46 - HackAttack: [SPI:Illegal connection state attack]
Dec 18 21:32:33 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 209.66.64.46 to 80.220.22.74
Dec 18 22:56:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
174.36.105.208 - Facebook LikeJacking Attack 9
[SID: 24476] Web Attack: Facebook LikeJacking Attack 9 attack blocked. Traffic has been blocked for this application
The client will block traffic from IP address 174.36.105.208...
69.91.1.195 - HackAttack: [SPI:Illegal connection state attack]
Dec 18 06:21:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 69.91.1.195 to 80.220.22.74
Dec 18 06:21:19 HackAttack: [SPI:Illegal connection state attack] ICMP packer fro...
58.218.199.227 - tried to hack my mac
This joker tried to hack into my mac using web sharing and port scanning.
Norton stopped it for now!
Can\'t anything be done about these ip ranges - like blocking them!...
91.190.87.74 - tried to hack my mac
This account tried to initiate web sharing several times on my Mac.
Tried through web sharing and secure web sharing.
Norton flashed a warning and blocked it (I hope)!...
74.53.2.87 - 74.53.2.87
Constantly being attacked by this IP address. Almost every five minutes. See report below.
74.53.2.87 Host blocked for 5 min SCAN (45254, 47046, 48070, 51398, 52166, 53702, 55238)
...
46.19.141.247 - Telenet
Hitting TELENET port repeatedly when there is no valid reason to try and connect to that on my network. The contact information is :
person: CRISTINA CASTRO
addre...
58.218.199.227 - log to webserver
several attempts to login on webserver over the last days until firwall disconnect the internet connection. Probabyl port scanning, but no proof for it. ...
93.109.180.119 - Port Scanning for the past 2 days
Wed Dec 14 16:53:35 2011
=>Found attack from 93.109.180.218.
Source port is 53621 and destination port is 63903 which use the TCP protocol.
Wed Dec 14 16:54:05 2011
=>Found attack from 93.10...
202.21.176.41 - HackAttack: [SPI:Illegal connection state attack]
Dec 16 01:26:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 202.21.176.41 to 80.220.22.74
Dec 16 01:26:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
221.194.46.176 - Kernel intrusion
Noticed many intrusions recently after turning on the routers syslog, however I understand that the router is doing it\'s job well, since every attempt has failed, who ever this is in China they can k...
202.21.176.41 - HackAttack: [SPI:Illegal connection state attack]
Dec 14 18:05:49 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 202.21.176.41 to 80.220.22.74
Dec 15 19:27:11 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
61.138.254.63 - More as 10 times per day TCP scans at port 80 5000
More as 10 times per day TCP scans at port 80 5000 How can I protect my self. On trying to accesing adress server responded radware...
202.102.153.70 - More as 10 times TCP scans at port 80 5000
More as 10 times per day TCP scans at port 80 5000 How can I protect my self. On trying to accesing adresses its an server login screen radware....
209.66.64.46 - HackAttack: [SPI:Illegal connection state attack]
Dec 15 12:58:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 209.66.64.46 to 80.220.22.74
Dec 15 15:10:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
94.100.30.165 - possable redirect blocked my malewarebites
this ip has attempted to redirect to its pages, this may be a us government tracker as ive been montered by the FBI for the last 2 months...
58.218.199.227 - attack
attempted to attack my computer, asest security did block it, but it comes up couple of times a day, what is this i don\'t know...
Getting a lot of network attacks from this IP.
Making my network run VERY slow and almost shutting me down at times. This is very annoying, how do I make them stop?...
114.182.76.238 - HackAttack: [SPI:Illegal connection state attack]
Dec 14 01:11:50 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 114.182.76.238 to 80.220.22.74
Dec 14 01:11:54 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
64.92.209.226 - Attempted Admin sign on
this ip 64.92.209.226 tried to access my Joomla Admin sign on for www.sportsstarphotos.com. there were 3 attacks from3 different IP addresses and I have blocked all 3 in the cpanel security ip blocke...
50.2.43.37 - Port scan attack me
My antivirys program personal wirewall is alert me that 50.2.43.37 is port scan attack me. someone is trying to hack me?
what shoud i do? im i protecded? ...
92.241.164.211 - Intrusion Attempt
Norton Blocked Intrusion Attempt X 2 on my computer from this IP Address also traces to Russia. This is the second month in a row this IP has attempted to get into my computer files...
124.239.195.131 - Intrusion.Win.MSSQL.worm.Helkern
Intrusion MSSQL worm Helkern Intrusion MSSQL worm Helkern Intrusion MSSQL worm Helkern Intrusion MSSQL worm Helkern Intrusion MSSQL worm Helkern Intrusion MSSQL worm Helkern worm Helkern...
61.235.46.146 - Intrusion.Win.MSSQL.worm.Helkern
Intrusion Win MSSQL worm Helkern kaspersky gave following alert in network attack category:-
\"Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.235.46.146 to local port 1434\"
Attack...
69.162.85.98 - uyarı
yavÅaklar internetime saldırıyorlarr zarar vercekler di İNSAI RAHATSIZ ETME SANA YAKIÅMAZ it it it tu tu tu tu tu tu tu tu tu tunk yok yok yok...
124.239.195.131 - Network Attack
09-12-2011 16:42:12 Unknown Denied: Intrusion.Win.MSSQL.worm.Helkern UDP from 124.239.195.131 to local port 1434
IP Address: 124.239.195.131
IP Address Country: China (CN)
IP Address Region: 22 B...
64.125.26.254 - HackAttack: [SPI:Illegal connection state attack]
Dec 9 02:54:41 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 64.125.26.254 to 80.220.22.74
Dec 9 04:03:57 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
61.235.46.146 - Me
Network Attack from UDP 61.235.46.146 to local port 1434. 12/08/2011 06:15:40PM México Time. Denied: Intrusion.Win.MSSQL.worm.Helkerm. Blocked network attacks by Kaspersky. These attacks...
75.77.189.110 - Attack
Alert Intrusion Prevention IPS Prevention Alert: VIRUS SQL Slammer Activity, SID: 1870, Priority: Medium 75.77.189.110, 3240, X1, 75.77.189.110.nw.nuvox.net ***.**.*.**, 1434, Alert Intrusion Preventi...
68.67.159.189 - Risky Connections
McAfee is closing this connection, i don\'t know how many time, maybe 2 o 3..i\'ve not only McAffe working but also Dr Web i hope to close this connection..i think that i will search for it personally...
221.194.46.176 - 221.194,46.176, 58.218,199,227, 58.218.199..250, 61.164.68.150
>Nortons Alerts >unused port blocking has blocked communications from (the above IP addresses all in China), local servers ports 9090, 5390, 2301, 8080, 8000, 3246, 7212 (and more)....continuou...
195.5.163.214 - RFI Attack
Hi,
This IP adress is trying to script attack our web server (195.5.163.214). This ip adress is known by many security websites as a RFI Attack server. Unfortunately, we are forced to deny access to ...
68.37.246.196 - HackAttack: [SPI:Illegal connection state attack]
Dec 6 23:05:19 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.37.246.196 to 80.220.22.74
Dec 6 23:05:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
68.37.246.196 - HackAttack: [SPI:Illegal connection state attack]
Dec 6 18:23:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.37.246.196 to 80.220.22.74
Dec 6 20:17:36 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
68.37.246.196 - HackAttack: [SPI:Illegal connection state attack]
Dec 6 11:51:25 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.37.246.196 to 80.220.22.74
Dec 6 11:51:33 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
68.37.246.196 - HackAttack: [SPI:Illegal connection state attack]
Dec 5 21:38:00 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.37.246.196 to 80.220.22.74
Dec 5 23:49:22 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
221.194.46.176 - Many log entries of 221.194.46.176:12200 in my router activity log.
Getting a lot of activity from this notorious ip. Isn\'t there some way that we can just have ANY unrequested internet activity coming from China blocked by default?...
68.67.159.189 - risky IP address
I received this 3 times in two days. McAfee blocks it what is it and is it dangerious. Is someone trying to hach into my system...
68.37.246.196 - HackAttack: [SPI:Illegal connection state attack]
Dec 4 23:16:39 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.37.246.196 to 80.220.22.74
Dec 4 23:16:43 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
68.37.246.196 - HackAttack: [SPI:Illegal connection state attack]
Dec 4 22:46:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.37.246.196 to 80.220.22.74
Dec 4 22:46:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
68.37.246.196 - HackAttack: [SPI:Illegal connection state attack]
Dec 4 13:17:47 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 68.37.246.196 to 80.220.22.74
Dec 4 13:48:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
91.226.212.41 - intrusive ip
My computer was attacked by an intrusive ip and my firewall sand me an alert. Thanks to report that fact and to add in your database....
124.239.195.131 - Network attack
Getting many attacks form china...this is just 1 of the ip addresses.Intrusion to local port 1434.Denied : Intrusion.win.mssql.worm.helkern .Any possible way to completely prevent this form happening?...
109.236.87.119 - Intrusion Alert
Intrusion attempt has been detected: NULL (no TCP flag set) scan
Inbound direction
Protocol: tcp
Remote Address: 109.236.87.119
Remote Port: 1935
Firewall has blocked this traffic so many times....
58.218.199.250 - Multiple scans denied
My ip log shows this ip from china trying over and over, way too many to count trying to open my router port. Why do they do this? What\'s their point?...
115.238.252.196 - "Multiple Hits"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 115.238.252.196
Number of attempts : 4
Time at last attempt : 12/2/11 ...
188.127.228.44 - Attack stopped by Norton
This site attempted to hijack my computer, Norton 360 disabled and stopped it. Beware! This is abviously some malware or malicious attack site.Thanks, that is all....
180.149.135.35 - HackAttack: [SPI:Illegal connection state attack]
Nov 28 10:54:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 180.149.135.35 to 80.220.22.74
Nov 28 11:19:39 HackAttack: [SPI:Illegal connection state attack] ICMP packer ...
94.69.17.255 - DoS:Smurf packets according to Netgear router
Router reported:
[DoS attack: Smurf] attack packets in last 20 sec from ip [94.69.17.255], Wednesday, Nov 30,2011 03:14:24
No one here using any computers at that time of night.
...
Kaspersky generates the following report, at least twice a day on every machine (35 machines).
Intrusion Win MSSQ1.worm.Helkern! IP address 219.148.1.91 UDP on local 1434 port...multiple times ever...
89.187.53.235 - Intrusion Prevention
My symantec Endpoint protection notified me of this IP Address trying to make a TCP connection to my system. Luckily Symantec stopped them from gaining access...
58.218.199.227 - It try several time to connec t to my computer
It try several time to connec t to my computer. How can i stop him to attack me? My panda soft ware tell me every time I use my computer.
It slow down my computer....
61.235.46.146 - got a message from kaspersky
got a message from kaspersky :
29-Nov-11 1:49:31 PM Unknown Denied: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.235.46.146 to local port 1434
Found people with similar problems. Kindly block this i...
72.39.237.153 - HackAttack: [SPI:Illegal connection state attack]
Nov 27 23:48:56 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 72.39.237.153 to 80.220.22.74
Nov 27 23:48:59 HackAttack: [SPI:Illegal connection state attack] ICMP packer f...
66.197.195.85 - Facebook
Some one tried to access my about form that ip address ?one week ago some tried to login on a kiosk from DC. Help me...
61.235.46.146 - win.mssql.worm.hellern
today 20 47 pm kaspersky found a worn helkern and blocked it from this i p address seems this is a regular accurance from this i p address
can any thing be done to stop this rat computer ?????...
196.29.120.74 - Melicious IP
Kaspersky is getting network attack alert from this ip I am gonna complaint about this.This ghana ip is hacking computers!!!!.Everybody who got this message from your firewall please complaint...
209.66.64.46 - HackAttack: [SPI:Illegal connection state attack]
Nov 26 03:11:19 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 209.66.64.46 to 80.220.22.74
Nov 26 03:17:05 HackAttack: [SPI:Illegal connection state attack] ICMP packer fr...
63.209.69.107 - Danger
I was forwarded here after opening up FireFox. I think a Virus was also download in the form of a .JAR file cause Java started running and promted me to allow Explorer firewall outbound access on XP P...
208.109.94.237 - 208.109.94.237 is attempting to login via ssh to our server
Time: Sat Nov 26 00:22:54 2011 +0100
IP: 208.109.94.237 (US/United States/ip-208-109-94-237.ip.secureserver.net)
Failures: 5 (sshd)
Interval: 300 seconds
Blocked: Permanent Block
Log entri...
212.148.1.91 - Intrusion fail
This adress attack my PC at 22:48:51
That\'s the second intrusion on my PC but Kaspersky block him.
I will know what I can do to stop it plz ...
Sorry but I speak english very well....
46.109.167.139 - Network Attacks
My Firewall Just send me a notification, and said that this ip address 46.109.167.139
is attacking your computer network
i don\'t feel so good ....
thanksss very much....
eset nod 32 is deticting port scan attack from 31.7.59.144 several times a day.. whats is it and how can i protect my pc. pls help me...
124.239.195.131 - kill this fucker.
IP Address: 124.239.195.131
IP Address Country: China (CN)
IP Address Region: 22 Beijing
IP Address City: Beijing
IP Postal Code
IP Address Area Code 0
IP Metro Code 0
IP Address Latitude: 39.92890...
210.21.221.156 - port scans and TCP_WAITS
seems like this IP is doing illegal stuff: port-scans, smtp-spamming, finger scans etc. Connactions sometimes appears to be used by proxy servers or TOR network...
79.212.208.21 - HackAttack: [TCP SYN Flooding]
Nov 22 13:53:05 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 79.212.208.21:26353 to 80.220.22.74:5909
Nov 22 13:53:05 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 79.212.208.21:2635...
219.148.1.91 - attack
n e t w o r k a t t a c k h a s b e e n blocked on my computer, computer attacked...
212.104.86.94 - worm
stop trying to load a worm on to my computer. this is starting to become a weekly event please. kaspersky internet sceurity denied intrusion.win.mssql.worm.helkern so sick of getting this. how can ...
58.218.199.250 - TCP scanned port list, 2301, 8118, 8008, 8088, 7212
TCP scanned port list, 2301, 8118, 8008, 8088, 7212 constant pinging of network. regular reporting of this addrwss in the firewall logs. thre attacks started today ...
58.218.199.147 - Getting lots Firewall alerts relating to this IP
=>Found attack from 58.218.199.147.
Source port is 12200 and destination port is 27977 which use the TCP protocol.
Mon Nov 21 16:43:48 2011
=>Found attack from 58.218.199.147.
Source port is 122...
I got tired of banning 180. but it keep change ip addresses many times for keep visiting my website and making me feel not comfort.. Where can I stop 180 from seeing my website and block google?
Her...
219.148.1.91 - firewall alert
dude lost vs. kaspersky, tries this bullshit for quite some time, get lost fucker, seriously.
this line is to screw the 25 word thing beep boop...
68.67.159.189 - Risky Connection Blocked
McAfee blocked my PC from making a potentially risky connection. This has been happening after I start my computer (not sure if it is only after I access the internet) as of 11/19/11.
IP address: 6...
68.67.159.189 - PC trying to establish connection
My PC was trying establish connection to this IP Address. Good thing my firewall prevented it.
This has happened 3x since last night. ...
68.67.159.189 - Risky Connections attempted
My home computer\'s macafee software stopped 4 \'risky connections attempted.\' Error message on report is \'run a dll as an app.\' Coming from IP 68.67.159.189
I can not access any internet without ...
94.245.121.253 - 94.245.121.253
Constant request from this IP 94.245.121.253
Enough already!
It appears to from Microsoft UK but have no idea what its trying to do. FIrewall has gone off its head constantly advising this IP is tryi...
91.202.61.170 - "E's still with us"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 91.202.61.170
Number of attempts : 8
Time at last attempt : 11/18/11 1...
219.148.1.91 - intrusion attempt: MS SQL Stack BO
02:12 Alert Intrusion: MS SQL Stack BO.
Intruder: 219.148.1.91(1224)
Risk level: High
Protocol: UDP
Attacked port: ms-sql-m(1434)
This is the first time my computer blocked an attack attempt from this...
92.37.36.28 - HackAttack: [SPI:Illegal connection state attack]
Nov 15 10:01:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.37.36.28
Nov 15 10:01:03 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.37.36...
66.57.29.170 - HackAttack: [SPI:Illegal connection state attack]
Nov 15 09:53:51 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 66.57.29.170
Nov 15 09:53:55 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 66.57.2...
92.37.36.28 - HackAttack: [SPI:Illegal connection state attack]
Nov 15 09:42:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.37.36.28
Nov 15 09:42:09 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.37.36...
66.57.29.170 - HackAttack: [SPI:Illegal connection state attack]
Nov 15 06:26:08 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 66.57.29.170
Nov 15 06:36:02 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 66.57.2...
66.57.29.170 - HackAttack: [SPI:Illegal connection state attack]
Nov 15 02:42:11 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 66.57.29.170
Nov 15 02:42:16 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 66.57.2...
92.10.102.31 - HackAttack: [SPI:Illegal connection state attack]
Nov 14 23:58:49 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.10.102.31
Nov 14 23:58:49 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.10.1...
92.10.102.31 - HackAttack: [SPI:Illegal connection state attack]
Nov 14 22:58:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.10.102.31
Nov 14 22:58:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 92.10.1...
41.105.37.101 - HackAttack: [SPI:Illegal connection state attack]
Nov 14 22:52:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 41.105.37.101
Nov 14 22:52:06 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 41.105...
77.72.56.247 - HackAttack: [SPI:Illegal connection state attack]
Nov 14 22:51:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 77.72.56.247
Nov 14 22:51:13 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 77.72.5...
78.15.25.114 - HackAttack: [SPI:Illegal connection state attack]
Nov 14 19:34:31 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 78.15.25.114
Nov 14 19:34:35 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 78.15.2...
118.122.188.27 - HackAttack: [SPI:Illegal connection state attack]
Nov 13 14:15:40 HackAttack: [SPI:Illegal connection state attack] TCP packet from [nas0] 118.122.188.27
Nov 13 14:19:10 HackAttack: [SPI:Illegal connection state attack] TCP packet from [nas0] 118.122...
173.212.194.92 - HackAttack: [SPI:Illegal connection state attack]
Nov 11 17:24:13 HackAttack: [SPI:Illegal connection state attack] TCP packet from [nas0] 173.212.194.92
Nov 11 19:22:43 HackAttack: [SPI:Illegal connection state attack] TCP packet from [nas0] 173.212...
222.187.221.28 - Firewalled
Intrusion detected: McAfee. Successfully blocked.
Why do we have to write twenty five words for it to show up on this page? I just explained it in five!...
80.67.160.70 - Intrusion / Attack tried from this IP Address
According to my internet security program the IP Address 80.67.160.70 tried an intrusion on my computer, which was fortunately blocked. The intrusion try was on November 6, 2011....
124.239.195.131 - Attack From this IP adress.
Unknown Denied: Intrusion.Win.MSSQL.worm.Helkern .UDP from 124.239.195.131 to local port 1434
IP Address: 124.239.195.131
IP Address Country: China (CN)
IP Address Region: 22 Beijing
IP Address Cit...
221.194.46.176 - Chinese address is attacking my network...
Nov/15/2011 23:01:26 Drop TCP packet from WAN 221.194.46.176:12200 24.98.28.254:6588 Rule: Default deny
Nov/15/2011 23:01:26 Drop TCP packet from WAN 221.194.46.176:12200 24.98.xx.xxx:8123 Rule: Def...
124.239.195.131 - Atack
11/15/2011 04:40:21.496 Alert Intrusion Prevention IPS Prevention Alert: VIRUS SQL Slammer Activity, SID: 1870, Priority: Medium 124.239.195.131, 2305, X1 ***.**.*.**, 1434, X3 11/15/2011 04:40:21.496...
219.148.1.91 - Attack
11/15/2011 10:01:52.624 Alert Intrusion Prevention IPS Prevention Alert: VIRUS SQL Slammer Activity, SID: 1870, Priority: Medium 219.148.1.91, 1224, X1 ..........., 1434, X* 11/15/2011 10:01:52.624 Al...
88.244.239.216 - hacking
I got alert that IP(88.244.239.216) trying to access my site, I dont\' know if there somebody need to hack my website.
Thanks & best regards
Gamal Hammad
gamal_hammad@hotmail.com...
109.235.55.11 - Help ban it
Identified as a malicious website by MalwareBytes
Type: outgoing
Ports: dynamic/private
Process :uttorrent.exe
Identified as a malicious website by MalwareBytes
Type: outgoing
Ports: dynamic/priv...
93.174.94.8 - malwarebyte allert
18:10:42 Erika IP-BLOCK 93.174.94.8 (Type: outgoing, Port: 54546, Process: firefox.exe)
18:10:42 Erika IP-BLOCK 93.174.94.8 (Type: outgoing, Port: 54589, Process: firefox.exe)
18:10:50 Erika IP-BLOCK ...
209.85.169.132 - DOS Attack
I am getting these all the time,, the other address\'s also come from 74.*.*.*... I am getting them on a regular basis.. Is this a problem??? or just a normally occurring event? They all say, [w...
109.235.55.11 - Keeps being blocked
really annoyed by it now, everyday it tries outgoing and malware byte keeps blocking it.
it also uses IP Switch and keeps attacking Full malware log:
02:36:15 USER1 MESSAGE Scheduled update executed...
169.254.83.178 - 169.254.83.178 Who is this trying to access my computers
169.254.83.178
Who is this trying to access my computers. What are they doing? They do not resolve to a URL or give any IP information...
70.85.140.250 - pls help
object : udp from 70.85.140.250 to local port 1434
result : denied:intrusion.win.mssql.worm.helkern
pls help. its frequent and i dont know whether i\'m safe or not and what is that asshole trying to ...
221.194.46.176 - Multiple attacks over days
This IP address, along with two others have been very intently trying to do port scans on my system for the last three days. ...
94.245.121.253 - Requesting incoming connection from this IP.
IP 94.245.121.253 blocked by ZoneAlarm. Requesting incoming connection from this IP.
Request made 11-06-2011 Protocol UDP Source IP: 94.245.121.253:3544
IP 94.245.121.253 blocked by ZoneAlarm. Reques...
184.154.90.138 - Constant attacks and recieved malware
I want this server removed, this is unacceptable, i have been receiving multiple attacks from different ip addresses from this location in Chicago Illinois and arlington heights...
69.31.111.133 - MALWARE AND FIREWALL ATTACKING
for 3 days multiple ips all from this specific area in Chicago Illinois and Arlington heights please shut DOWN. this is irritating, constant alerts, also had to remove malware...
64.37.231.135 - ATTACKING MY PC
PEople from this ip is attacking my pc, also all firewall alerts are from multiple ips that are all tracked back to Chicago Illinois and Arlington heights...
72.246.184.13 - Land Attack
FNBT.COM BANK is recieving a Land Attack from 72.246.184.13, we are getting alerts from the IP Address and have been for over 2 hours ...
74.63.243.194 - alert
I get repeated attacks from this direction.
I think the firewall prevents attacks but are very common.
Not how to avoid this....
208.76.54.68 - Web Attack: Malicious Exploit Kit Website
\"Network traffic from 208.76.54.68 matches the signature of a known attack. Network traffic from zveds.info/7htsp56x/?1 matches the signature of a known attack.\"
This message from newest ...
109.235.55.11 - blocked blocked blocked
do complaints make any difference, can\'t this IP address be blocked or investigated ? it gets blocked every time but is very annoying. seems like something should be done about this....
94.245.121.253 - Multiple requests on my mchaine from this IP address..see example
udp Incoming 94.245.121.253 3544 192.168.0.110 50297 05/11/2011 17:47:25
udp Incoming 94.245.121.253 3544 192.168.0.110 50297 05/11/2011 17:47:17
udp Incoming 94.245.121.253 3544 192.168.0.110 50297 ...
74.52.60.162 - MyDoom Virus Activity
Cisco IPS is reporting this IP several times today
time: nov 03, 2011 12:47:12 UTC offset=60 timeZone=GMT+01:00
signature: description=MyDoom Virus Activity id=3135 version=S105 type=vuln...
208.73.210.125 - 208.73.210.125 being accessed
when connected to the network, some program, trojan is trying to access 208.73.210.125.
i would love to know what piece of software is doing this...
70.85.140.250 - attack from 70.85.140.250
Same as above, and same internet adress, also an attack on the lokal port 1434 but just one try..do I have a virus on my computer that tries to communicate or did Kaspersky stop an attack?...who the h...
76.10.205.167 - HackAttack: [SPI:Illegal connection state attack] ICMP packer
Nov 1 23:09:43 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 76.10.205.167
Nov 2 04:02:55 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 76.10....
95.8.197.31 - Tried to access admin area of my Website
This ip tried to hack into my admin area of my website. I am getting tired of these twits from Turkey.
Is there a way to block all traffic from Turkey. The local authorities won\'t do anything so blo...
221.194.46.176 - Port scanning
Dear Sir
I got this messege form my firewall \" Detected Port Scanning attack from 211.194.46.176\"
I would like to know more about this attack
thanks and regards ...
109.235.55.11 - Hacking threat
This IP was caught attacking my ports. I received the warning from Malwarebytes, and modified the ports, but the IP continues to attack my network....
69.73.188.251 - attack
My Router firewall is reporting that this IP address has been trying to access my ports. for what purposes I do not know but I want it stoppped Please....
91.202.61.170 - "Continuous Campaign"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 91.202.61.170
Number of attempts : 8
Time at last attempt : 10/27/11 0...
91.202.61.170 - "My my, What a Busy Hacker"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 91.202.61.170
Number of attempts : 10
Time at last attempt : 10/27/11 ...
91.202.61.170 - "Constant Hacking"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 91.202.61.170
Number of attempts : 9
Time at last attempt : 10/27/11 0...
70.85.140.250 - complaints about 70.85.140.250
This is an another complain 70.85.140.250 I was lucky my kaspersky stop
the attack. I got a question to you guys does anyone of you have (vuze) installed I got malwarebytes and it stop vuze from conn...
91.202.61.170 - Persistent Hacker
Security alert type : IP Subnet Broadcast Amplification
IP source address : 91.202.61.170
Number of attempts : 19
Time at last attempt : 10/25/11 ...
91.202.61.170 - "New Tennant"
Well, he\'s not going away. Been kicking the firewall since my last post. Very persistent behavior. Would like to see him off the network, the Chinese hackers are going to like some else plucking t...
91.202.61.170 - IDS proto parser from 91.201.61.170
Warning 15 days 01:58:45 (since last boot) IDS proto parser : tcp data on syn segment (1 of 1) : 91.202.61.170 XXXXXXXX 0140 TCP 80->22622 [S.A...] seq 84049046 ack 2075994375 win 512
Warning ...
91.202.61.170 - "Multiple Attempts"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 91.202.61.170
Number of attempts : 12
Time at last attempt : 10/24/11 ...
70.85.140.250 - Who are these people who attack my computer?
I regularly get attacks like this, how do I know where they come from? Are the IP address is actually one my antivirus detects? Thank you in advance for your answers....
94.100.30.164 - Out going
I am getting the same thing as the previous post.
A message pops up once in a while saying it blocked outgoing from this IP on Port 62859...
70.85.140.250 - worm slammer
it try to get in my pc! A worm slammer. this is 10/20/11 on port 1234 my kaspersky did stop it the ip is 70.85.140.250 ...
63.118.252.131 - Alert
10/20/2011 01:57:18.288 Alert Intrusion Prevention IPS Detection Alert: BAD-FILES Malformed PLS File, SID: 7040, Priority: Low 63.118.252.131, 80, Xx xxx.xxx.xxx.xxx, 28750, x
2 10/20/2011 01:5...
58.218.199.227 - 58.218.199.227
Firewall alert. This IP has been attemping several times a minute to scan my computer. This appears on our stealth mode log. ...
222.45.235.77 - Access Alert
We had numerous firewall access attacks from IP 222 45 235 77 over the last twenty four hours, we will report any other attempts ...
61.235.46.146 - Network Attack
Network Attack. Kaspersky detected. No other complaint. No other complaint. No other complaint. No other complaint. No other complaint. No other complaint. No other complaint....
68.87.71.230 - Detected port sniffing by firewall
Detected port sniffing by firewall ESET Smart Secutiry 5. Got a message out of the sudden warning that an intrusion was detected fom the ip address....
8.5.1.39 - complaint about 8.5.1.39
I am noticing several unwanted 443 connections from my machine to this host. INFECTED SERVER WITH MALICIOUS VIRUSES&MALWARE REPORTED AND BLOCKED BY MALWAREBYTES...
Security alert type : IP Subnet Broadcast Amplification
IP source address : 61.147.73.146
China China, Always China, Night & Day, Day & Nighrt China China China Chi...
58.218.199.147 - syn flood
I\'ve got firewall alert with this IP on port 12200. The firewall alert tells me this IP adress is doing SYN flood attack on my router....
61.61.20.132 - Attacks
Malwarebytes and McAfee blocks this ISP attack multiple times everyday and several times an hour. Has been happening for a couple weeks. How do I block this ISP?...
83.222.124.249 - Malwarebytes blocking this IP
My MalwareBytes Antimallware software is blocking this IP (IP-BLOCK 83.222.124.249) (Type: outgoing). It happened 3 times since i installed it: on 13. October 2011: at 00:54, 1:50, and at 5:48. I chec...
213.190.51.234 - 213.190.51.234
Keeps scanning my firewall with: IDS proto parser : tcp null port (1 of 1) : 213.190.51.234 xx.xx.xx.xx 0048 TCP 0->445 [S.....] seq 3351388781 win 65535...
58.218.199.147 - massive port attack...
I keep getting hit by this ip address from their port 12200 to my (http) port 80....
annoying. I am really getting tired of Chinese cyber-terrorist attacks....
58.218.199.147 - Pings my Router
Received Security alert from my router, I\'m not sure what is happening but it seems suspicious. It may be connected to unusual telephone calls I\'ve received. An Asian sounding person says that there...
174.36.241.116 - "Very Determined"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 174.36.241.116
IP destination address : 76.227.65.191
Number of attempts ...
193.105.210.81 - "Executable File Upload Attack."
WordPress Firewall has detected and blocked a potential attack!
Web Page: www.osx64.com//wp-content/plugins/1-flash-gallery/upload.php?action=uploadify&fileext=php
Warning: URL may contain dang...
174.36.241.116 - "Seems quite eager"
Security alert type : IP Subnet Broadcast Amplification
IP source address : 174.36.241.116
IP destination address : 76.227.65.191
Number of attempts ...
118.139.184.14 - Attack
Alert Intrusion Prevention IPS Prevention Alert: WEB-CLIENT Obfuscated JavaScript Code 4, SID: 5206, Priority: Medium 118.139.184.14, 80, X1, ip-118-139-184-14.ip.secureserver.net ***.***.***.**, 2880...
193.105.210.81 - Wordpress Firewall Alert
Plugin not installed.
WordPress Firewall has detected and blocked a potential attack!
Web Page: http://*******.com/wp-content/plugins/1-flash-gallery/upload.php?action=uploadify&fileext=php...
221.194.46.176 - port scanning
As is explained by the person below, Im receiving frequent multiport tcp requests from this chinese address, as well as tcp requests from Limestone network in TX....
38.105.9.164 - illegal downloading
From: Sony Pictures Entertainment [mailto:specopyright2@mc.mediasentry.com]
Sent: Saturday, October 01, 2011 12:54 PM
To: Abuse
Subject: Case ID 1233353013 - Notice of Claimed Infringement
Saturday,...
69.181.252.195 - Port Scanning
My port is attacked by the above IP Adress whic is notified by ESET Personal Firewall. Iam from India and I dono why this IP has been continously attempt to scan my port....
93.114.40.92 - Slows down netowrk connection
computer is using iexplorer.exe for an outgoing on different ports (simillar to a port scan but it\'s outgoing) to this IP adress. is used by an infected webtv program to simulate legitmate connection...
219.148.1.91 - 01.10.2011 19:26:55 Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.148.1.91 to local port 1434
01.10.2011 19:26:55 Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.148.1.91 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.148.1.91 to local port 1434 Abse...
64.74.223.39 - McAfee Net Guard Blocked IP 64.74.223.39
When I access http://filmessegundaguerra.blogspot.com/ and my McAfee Total Protection (Firewall Net Guard) say \"IP 64.74.223.39\" isn´t secure and it was blocked.
Anybody know...
122.224.5.45 - potentially malicious site
malwarebytes anti malware has reported that several attemtps have been made by this potentially malicious website to access my system request take necessary action to prevent further attemtp by this s...
193.107.16.156 - potentially malicious site
my fire wall malwarebytes antimalware blocked innumerable attempts to access my laptop and reported that the sameis a potentially malicious website. hence request take necessary action to block this i...
109.235.55.11 - fire wall alerted that a malacious attempt is being made
My firewallhas alreted that there has been a malacious attempt to access my laptop.almost every attempt has been blocked my malwarebytes antimalware software kindly take necessary action to prevent an...
192.168.1.114 - 192.168.1.114
This ip keeps trying to access my wireless router. every 5 to 10 minutes. I have him blocked, but I am not sure this is enough. i need help...
We have this alerts on our firewall every 20 minutes: \'Smurf Amplification Attack Dropped\' , from IP Adress 129 . 82 . 138 . 38...
219.148.1.91 - Attack
28/09/2011 12:39:13 Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.148.1.91 to local port 1434
--------------------------------------------------------------------------
27/09/2011 21:27:45 ...
64.94.107.54 - IP 64.94.107.54 Internap Network Services Corporation
This IP attempted unauthorized entry
IP Address:
64.94.107.54
IP Address Country:
United States (US)
P Address Region:
CA California
IP Address City:
Pasadena
IP Postal Code
IP Address Area Code
626
...
58.218.199.147 - Detected port scanning
Every 5 min my internet firewall shows a blocked attack from this ip address. The attack is happening even if i am on a dynamic ip address. Although my firewall blocks it but the annoying pop ups are ...
58.218.199.147 - Firewall alert
Firewall alert Many time Everyday idont know y from the seame ip from china
i dont know if this hacker attack or normal things that happen every day to peoples or it was a mistake from the host intern...
67.88.220.21 - 67.88.220.21
Dear Team,
I am from Germany and somebody was scanning my notebook from this IP adress...67.88.220.21.
Please investigate as soon as possible.
Make sure it does not happen....
208.93.85.155 - HackAttack: [SPI:Illegal connection state attack]
Sep 19 17:35:01 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 208.93.85.155
Sep 19 17:35:04 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 208.93...
67.192.106.155 - WTF?
I dont know why but this IP keeps trying to connect to my PC...My firewall always blocks it but it still can not be good....
83.167.227.32 - HackAttack: [SPI:Illegal connection state attack]
Sep 16 16:50:26 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 83.167.227.32
Sep 17 01:26:05 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 83.167...
116.228.188.162 - Firewall Alert for this ip address.
Firewall Alert for this ip address. Hacker tried to login into server several times with no success. I see this ip address in several of my logs from Sept 12....
24.5.175.215 - HackAttack: [SPI:Illegal connection state attack]
Sep 14 19:45:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.5.175.215
Sep 14 19:45:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.5.1...
204.11.109.23 - IP 204.11.109.23
My firewall reported attempt to enter my computer on 9/15/2011 around 6:30 pm. IP 204.11.109.23. Reported by Mcaffee. Why is there a character minimum. Wow, this is like.......
165.193.42.72 - send all the time alart
Time: Thu Sep 15 14:40:38 2011 +0300
IP: 165.193.42.72 (US/United States/at1-scan006.scanalert.com)
Hits: 11
Blocked: Temporary Block
Sample of block hits:
Sep 15 14:40:23 israel10 kernel:...
109.235.55.11 - Outgoing blocked by Malwarebytes everytime IE8 is close
This appears to have associated with IE and it is blocked every time the browser is closed. Is there any resolution for removal. Thus far a full scan by Malwarebytes and by AVG 2012 have not isolate...
204.11.109.23 - 204.11.109.23 from oakland calif. just tried to connect to my pc...blocked by mcafee
204.11.109.23 from oakland calif. just tried to connect to my pc...blocked by mcafee. who is this? please investigate this user and shut down any illegal activity....
218.206.31.132 - SSH access atempts
This IP address keeps trying to gain access to our systems since weeks via ssh brute force. The IP is beeing automatically blocked by our firewall.
...
68.188.81.252 - SSH access atempts
This IP address keeps trying to gain access to our systems since weeks via ssh brute force. The IP is beeing automatically blocked by our firewall.
...
222.122.13.156 - SSH access atempts
This IP address keeps trying to gain access to our systems since weeks via ssh brute force. The IP is beeing automatically blocked by our firewall.
...
60.217.235.5 - SSH access atempts
This IP address keeps trying to gain access to our systems since weeks via ssh brute force. The IP is beeing automatically blocked by our firewall....
78.15.41.86 - HackAttack: [SPI:Illegal connection state attack]
Sep 11 01:40:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 78.15.41.86
Sep 11 01:40:12 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 78.15.41...
140.239.191.10 - wtf is xo communications and why do i see it on my computer...
subject says it enough at at at at at at at at at at at at at at at at at at at at at at at at ...
204.11.109.23 - McAfee blocked 'Risky Connection'
Do not know what they are trying to do....?
Messaged their contact us form to see what their deal is.
Why is there a character minimum? a...
221.1.220.185 - Persistent port scanning
Hundreds of port scans coming off this IP daily. Stopped for about a week when I reset my address but it\'s back with vengeance. It locks up the firewall and knocks me out of whatever I am doing.
...
58.218.199.227 - attempts to connect
several attempts in a row to connect to my computer through different ports (2479, 7212, 5390, 8080 - in that order) from 58.218.199.227:12200 were blocked by my firewall. ...
216.245.196.122 - attempt port attack
had this going on for about 5 days now, good thing my firewall is catching the
ip and letting me know . just wish someone do something about it , cause I
talked to one of the people there, name Austin...
94.188.21.147 - firewall alert
Unknown Denied: Intrusion.Win.MSSQL.worm.Helkern UDP from 94.188.21.147 to local port 1434 , on 02 09 2011 , ,,,,, , ,, , , , , , , , , ,...
192.168.1.114 - N/A
This address keeps connecting to my network. This has been going on for several days now. It is a computer from outside of my home network...
210.61.79.212 - "Constant Alerts"
Attacks from this Address coinciding with attacks from 58.53.128.193
Security alert type : IP Subnet Broadcast Amplification
IP source address : 210.61.79.212
Number of at...
58.53.128.193 - "Constant Alerts"
Multiple attempts recorded of security breaches, Security alert type : IP Subnet Broadcast Amplification
IP source address : 58.53.128.193
Number of attempts ...
220.178.16.98 - 5060
Blocked incoming UDP packet from 220.178.16.98:5060 to 75.128.2.198:5060
Blocked incoming UDP packet from 220.178.16.98:5060 to 75.128.2.198:5060
Blocked incoming UDP packet from 220.178.16.98:5060 to...
216.245.196.122 - ALL THE TIME
Thu Sep 01 02:15:03 2011 Blocked incoming TCP connection request from 216.245.196.122:12200 to 75.128.2.198:8123
[INFO] Thu Sep 01 02:15:03 2011 Blocked incoming TCP connection request from 216.245.19...
210.4.170.180 - 210.4.170.180
Blocked incoming UDP packet from 210.4.170.180:21919 to 75.128.2.198:20726
Blocked incoming UDP packet from 210.4.170.180:21919 to 75.128.2.198:20726
Blocked incoming UDP packet from 210.4.170.180:219...
222.187.221.28 - intrusion
while using firefox, browsing medical sitegot a pop up :This IP (222.187.221.28) was trying to connect to my PC, detected by McAfee on 8/31/2011...
72.3.230.24 - 72.3.230.24 HIGH LEVEL ATTACKON PORT 80
IP Address: 72.3.230.24
IP Address Country: United States (US)
IP Address Region: TX Texas
IP Address City: Fort Worth
IP Postal Code
IP Address Area Code 817
IP Metro Code 623
IP Address Latitude:...
31.3.246.80 - TCP Syn/Fin packet dropped
Not sure what is going on but this joker keeps hitting my firewall. He hasn\'t made it in, but he sure is persistant
31.3.246.80, 0, WAN, h31-3-246-80.host.redstation.co.uk...
192.147.69.84 - Unwanted gifts
This bugger is sending trojan programmes in with a quasi government e-mail in the hope that there are enough unsuspecting people out there to fall for it....
IP 204.11.109.23 from Oakland, Calif just attempted unauthorised entry.
IP 204.11.109.23 from Oakland, Calif just attempted unauthorised entry.
IP 204.11.109.23 from Oakland, Calif just attempted una...
58.218.199.147 - Actively scanning
- Probably a compromised host with a random ip attack pattern
- what\'s interesting is that it\'s always from the same IP on multiple posts
Aug 29 10:06:56 <home_net_gwt> kernel: [hammer] : IN=...
58.218.199.227 - 58.218.199.227
I am getting dozens of warnings from Malware Bytes that this address is being blocked as potentially harmful. I had been hacked a couple weeks ago and spam was sent to everyone on my email contact lis...
208.76.54.68 - Intrusion attempt, High risk
Norton told me this ip was trying to intude my hard drive and crash the computer but the attempt was blocked. So I hoped this helped and i also hope you can stop this person.
P.S - This crased the pl...
94.212.230.212 - HackAttack: [SPI:Illegal connection state attack]
Aug 26 23:16:56 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.212.230.212
Aug 26 23:16:59 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 94.21...
114.45.178.86 - HackAttack: [SPI:Illegal connection state attack]
Aug 26 21:26:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 114.45.178.86
Aug 26 21:26:14 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 114.45...
173.89.32.255 - HackAttack: [SPI:Illegal connection state attack]
Aug 26 16:57:07 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 173.89.32.255
Aug 26 16:57:10 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 173.89...
219.84.228.251 - HackAttack: [SPI:Illegal connection state attack]
Aug 26 16:56:42 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 219.84.228.251
Aug 26 16:56:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 219.8...
59.93.113.107 - HackAttack: [SPI:Illegal connection state attack]
Aug 25 15:42:23 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 59.93.113.107
Aug 25 15:42:24 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 59.93...
58.218.199.250 - Intrusive behaviour
This website 58.218.199.250 keeps trying to get into my computer throught the skype port 80. Fortunately my anti-malware keeps it out, but it is an invasive nuisance and an ongoing security threat.
Un...
68.94.156.1 - named: dropped malicious resp from 68.94.156.1
rtp: RTCPGetReports: Use symmetric owd
many blocked fw connections.
INF 2011-08-23T08:30:18-05:00 rtp: RTCPGetReports: Use symmetric owd
INF 2011-08-23T08:36:08-05:00 rtp: Previous log entry...
209.123.113.226 - 209.123.113.226 from Morris Plains, New Jersey, USA
Above IP, 209.123.113.226 from Morris Plains, New Jersey, United States of America attempted unathorised entry. Above IP, 209.123.113.226 from Morris Plains, New Jersey, United States of America attem...
58.218.199.250 - Watchguard keeps blocking this IP Address
Our network has been under attack by this IP address. This is insane! how do we keep this from happening. It is shutting my firewall down ...
85.159.233.161 - Alert
08/22/2011 02:47:36.048 Alert Security Services Gateway Anti-Virus Alert: IFrame.JX (Trojan) blocked 85.159.233.161, 80, X1, s0.freeserials.com 08/22/2011 02:47:36.048 Alert Security Services Alert S...
58.218.199.147 - 5 attacks in last 2 days
I am getting the following messages from my router:
21 Aug 2011
TCP Packet - Source:58.218.199.250,12200 Destination:MyIpAddress,73 - DOS
TCP Packet - Source:58.218.199.250,12200 Destination:MyIpAddre...
89.187.53.210 - Attacking
I have recieved many attacks, intrusion attempts, from this IP adress in the last few days. As well as other IPs from the same location. Not cool. ...
68.169.92.53 - like 10 different 'malicious url' alerts
with avast when i went to bannedinhollywood.com with this ip.
so yeah. >_<
no harm done though, so everything is alright. :D
i really love avast. it blocks everything for me. <3...
115.56.123.169 - someone from this email was trying to access my network
My firewall detected someone from ip 115.56.123.169 was trying to access my network, but was blocked, also my rovio robot started to walk by itself after this, so I blocked all ports the rovio robot w...
68.169.92.53 - constant attact on my computer
ip address 68.169.92.53 is trying to get to my computer, it\'s been done countless time every day. I wonder what I can do about it. I guess this one way.
thanks...
129.82.138.38 - Unsolicited Inbound ICMP Connections
This past week i\'ve been receiving unsolicited inbound ICMP connections attempts from 129.82.138.38 to my router ip of 192.168.1.64:8, every 10 minutes. I would like it to stop....
58.218.199.147 - port scaning
port sacning almost 10 times a day. How can I put tis ip in black list? or, someone can do somthing about? Thank you very much...
109.235.55.11 - connections from
109.235.55.11 keeps trying to connect on port 6969 , firewall alerts me ,6969 is common port for gatecrasher brute force hack. might be a tracker for torrents....
190.43.245.55 - inbound connection attempt
Keep on getting inbound connection attempts from isp address 190.43.245.55 (Telefonica de Peru). Don\'t know who they are and why they keep on trying to access my computer but probably for hacking pur...
216.245.196.122 - multiple cases of Limestone Ntwk testing my firewall ports
Seing hundreds of attempts to access my computer network through opened router ports.
Unknown inbound sessions from: 208.115.219.10 & 216.245.196.122 have so far been blocked by my firewall....
109.235.55.11 - blocking alot.
My firewall has been blocking alot of connections from this ip of incoming connections. Getting really annoying now because it also lags my computer slightly....
79.16.0.135 - 79.16.0.135
Whom ever is registered to the IP address of 79.16.0.135 has repeatedly tried to gain access to my systems.
Please make whom ever cease and desist.
Thank you.
...
58.218.199.147 - 58.218.199.147
Getting numerous Firewall alerts relating to this IP
TCP Packet - Source:58.218.199.147,12200 Destination:86.23.100.87,80 - [DOS]
TCP Packet - Source:58.218.199.250,12200 Destination:86.23.100.87,80...
58.218.199.147 - 58.218.199.147
ip addresses trying to access my computer, several....several times.Being notify by norton. I am in canada. What shall I do ??? This ip is from China....
173.192.117.66 - Blackhole Toolkit
This I.P. was launching an attack via Blakchole toolkit, over an advertisment located on deviantart.com . It has been detected by symantec endpoint protection on the 8/15/2011 14:40:12...
64.4.35.253 - Its MS
This address belongs to ns1.msft.net msnhst.microsoft.com and at a guess is related to MSN messenger. Nothing to me suggests hacking activity, but I\'ve blocked it just to be on the safe side. ...
208.73.210.125 - attack
je suis francais et j\'aimerais savoir pourquoi j\'ai des tentative de conection sur plusueur port venant le ip 208.73.210.125
bloquer par malwarebytes anti-malware
type outgoing
procesuce iexplorer...
79.174.72.66 - cheap nike shox
Women are not always like to wear high heels, may know more than 7 cm high heels can damage the pelvis? So liberate your feet on it. Put on a pair nike shox r3 shoes, activate your athletic, cheap N...
my modem enters the following log file every few seconds for the last 19 hours its been switched on, this in turn causes it to slow down a lot the last address in the entry is my wan ip address provi...
118.139.184.14 - Intrusion Prevention
IPS Prevention Alert: WEB-CLIENT Obfuscated JavaScript Code 4, SID: 5206, Priority: Medium 118.139.184.14, 80, X1, ip-118-139-184-14.ip.secureserver.net i seen this ip before in my logs lurking about ...
58.218.199.250 - same as everybody!
The ip address 58.218.199.250 and the ip address 58.218.199.147 (same people I think) are trying to access my computer through different ports but mainly port 12200.
Can\'t we completely block them?...
24.44.120.248 - HackAttack: [SPI:Illegal connection state attack]
Aug 12 19:54:16 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.44.120.248
Aug 12 19:54:19 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.44...
67.169.24.19 - HackAttack: [SPI:Illegal connection state attack]
Aug 12 19:51:37 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 67.169.24.19
Aug 12 19:51:40 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 67.169...
60.190.223.137 - Unsolicited TCP packet sent--blocked by firewall
An unsolicited TCP packet was sent to port 65500 from remote port 6000. Incident occurred on Aug 11, 2011 @ 14:11:44 PDT (UTC -0700)....
24.35.49.133 - HackAttack: [SPI:Illegal connection state attack]
Aug 11 17:35:04 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.35.49.133
Aug 11 17:35:21 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 24.35....
24.199.16.0 - Hooked up to my computer last night
I got a message from my newly Installed Zonealarm 9.2.106.000--firewall that my computer had a new network added to it overnight, with the new IP being 24.199.16.0 or Road runner network in Californi...
221.194.46.176 - Times are GMT+2, seems a Windows machine
Aug 9 06:35:23 LOLHOST kernel: [10228544.082714] IN=eth1 OUT= MAC=00:05:1c:01:06
:92:00:0e:83:06:4c:72:08:00 SRC=221.194.46.176 DST=MY_IP LEN=148 TOS=0x0
0 PREC=0x00 TTL=43 ID=25945 DF PROTO=ICMP TYP...
221.192.199.49 - DOS
Fri, Aug 5th 2011, 3:01pm, TCP Packet, Source:221.192.199.49, DOS attack, 4 times using 4 different local ports, remote port 12200.
No noticable effect, but logged in firewall...
94.100.30.164 - out going
not sure? what it is. my malware bytes\' anti-malware keeps bring it up IP block 94.100.30.164 (type out going, not sure what this meens thank you....
91.220.0.15 - call-out
Malware bytes says my machine is trying to call out to this ip address, which is traced to same source as 91.220.0.35. Don\'t know if it is malicious or not. Not a techie....
58.218.199.147 - 58.218.199.147.
My firewall alarmed me to the fact that 58.218.199.147. is scanning my computer. How do I prevent this happening? Surely no-one has the right to access my IP address...
221.192.199.49 - attack from 221.192.199.49
several connection attempts or attacks from IP adress 221.192.199.49 on destination ports: 7212, 73, 8008, 800, 8085 all TCP from TCP source port 12200 ...
174.133.213.18 - User(s) from this IP address are trying to connect without any privilleges to our server pointed at address: 78.47.239.25
Here you have our data log (truncated):
Aug 7 03:05:14 wizardbit sshd[8416]: Failed password for invalid user julian from 174.133.213.18 port 45093 ssh2
Aug 7 03:05:14 wizardbit sshd[8417]: Received...
63.221.143.14 - high risk attack.
very often received by firewall alert about this
attacked from this ip address: 63.221.143.14.
Server rate this as high risk attacker.
i am using 2wire router. ...
111.118.165.98 - Blocked IP
Hello i am an admin for i-net and my account was blocked when i was attempting to login, because my password is fairly complex.
Then the site timed out and said my IP was blocked by firewall
Please u...
221.194.46.176 - wtf from china!?
How the hell did this ip find me all the way from fkin china?? isnt there a solution, cuz, its happening ALOT! causing spikes and stuff. i swear if china was close ill go and smash the pc on his head!...
221.194.46.176 - 221.194.46.176
Firewall has blocked over 100 tcp attempts by this IP over the last week.
Believe all were stopped yet wondering why the attacks since all of my ports are in stealth mode. Have done scans both intern...
128.9.160.132 - Network Attack notification
We experienced an alert about 128.9.160.132 showing a Network Attack Notification involving 5 unknown packets. I have received over twenty of these alerts during the last two days....
58.218.199.227 - Attempted DOS attack
Firewall blocked and logged the following :
Source IP: 58.218.199.227
Remote port: 12200
Attempted DOS attack
1 attempt on 2 August 2011
No noticable effects other than logged in external hardware f...
221.194.46.176 - Attempted DOS attack
Firewall blocked and logged the following :
Source IP: 221.194.46.176
Port: 12200
Attempted DOS attack
6 attempts, over 1.25 hours, on 2 August 2001
No noticable effects other than logged in externa...
172.183.7.81 - IS TRYING TO ATTACT MY COMPUTER OVER AND OVER AGAIN
THIS PERSON IS CONSTANTLY ATTACKING MY COMPUTER....POSSIBLY FOR CRIMINAL REASON.....I AM USING KASPER SKY AND THANKFULLY IT HAS BLOCKED ALL THE ATTACKS BY THIS ATTACKER......
BUT STILL THIS PERSON IS ...
8.5.1.43 - Malwarebytes blocking every 3 seconds
My Malwarebytes is constantly telling me its blocking this site from accessing my pc. Its getting annoying. Would love to know why some company in WA is trying to get into my PC
...
62.63.214.2 - Daily attacks showing in Firewall Alerts
Attacks to try and guess username and/or password to a server. Consistantly tries to access our servers over the course of several hours. Access is attempted almost daily in early morning hours. ...
97.64.173.21 - Daily attacks on Server
Used brute force dictonary attack to try and guess username and/or password to server. Was unable to succeed. Shows up on server log as an attempt to login to domain almost daily....
221.1.220.185 - 221.1.220.185. China Attacking again
This is becoming a daily thing. A scan for open ports from some server in china...
We need to BLACK list the China Network and let them know this criminal action is NOT allowed to continue.
...
70.37.82.196 - Seems like a large scale attack
I get hundreds of these firewall alerts everyday. Most appear to come from China... this one appears to come from Microsoft. Hmmm....
Wed Jul 27 07:27:40 2011
=>Found attack from 70.37.82.196.
S...
120.71.14.43 - Large scale attack from China
Seems to be a part of a large scale, coordinate port scan or some other type of attack. I get hundreds of these alerts everyday. Almost all of them come from China.
=>Found attack from 120.71.14....
68.94.157.1 - udb scan
Security alert type : Port Scan
Protocol type : UDP
IP source address : 68.94.157.1
Time at last attempt : 7/28/11 01:53:37 PM
Number of port...
71.225.101.91 - HackAttack: [SPI:Illegal connection state attack]
Jul 28 21:43:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 71.225.101.91
Jul 28 21:43:45 HackAttack: [SPI:Illegal connection state attack] ICMP packer from [nas0] 71.225...
85.17.92.36 - An Intrusion Attempt by waltrate.org
Received following notice from Norton: \"Network traffic from waltzate.org matches the signature of a known attack. the attack resulted from \\DEVICE\\HARDDISKVOLUME1\\PROGRAM FILES\\MOZILLAFIREF...
80.42.218.198 - Intrusion alert
This IP from United Kingsom tried to attack me twice on 22.07.2011 , but my firewall blocked it.
Attack Name:
OS Attack: MS RPCSS Attack SVE-2004-0116 2...
88.117.100.63 - Intrusion alert
This IP from austria tried to attack me twice at the same time, but my firewall blocked it.
Attack Type:
OS Attack: MS RPCSS Attack CVE-2004-0116 3...
68.109.118.31 - hacking passwords
68.109.118.31 misbehaving . This IP is hacking passwords and connecting to those accounts and accessing information from those accounts. CT Connecticut.Manchester, united States of America....
68.87.74.166 - Instrusion
Norton Security Suite noted an intrusion attempt from this IP I am not sure if this is a hack or what it is, Watch for this...
58.218.199.147 - ip addresses trying to access computer
being notified by malware bytes several ip addresses trying to access (incoming and outgoing) 221.192.199.49 , 121.125.204.239, 59.34.40.99, 89.28.71.169, 58.218.199.147, 222.69.7.3, 89.28.18.137 amon...
69.73.144.72 - 2 attempted ssh log-ins per second to my static IP address
My router keeps getting overwhelmed by attempted ssh logins from this address 69.73.144.72 It looks like it is owned by a company named \" dedicated interactive \"...
64.111.211.172 - 64.111.211.172 outgoing blocked
My anti-virus keeps on popping a message that an outgoing connection to this ip was blocked. I do not have any browser or any application open on my machine.
I have also noticed that any search result...
58.218.199.250 - 58.218.199.250
This source has been placing incoming as well as out coming alerts. Just this morning before 5:20 am EST I have seen it 5 times and now at 5:22 am Sunday July 22nd 2011, I also have:(122.224.54.49.
G...
205.209.161.156 - TCP scans
For the umpteenth time in the last two day\'s I\'ve been having TCP scans from 205.209.161.156 -:
Traffic from IP address 114.46.230.189 is blocked from 07/23/2011 23:50:56 to 07/24/2011 07:50:56.
...
109.235.55.11 - Trojan "Gatecrasher"
My firewall has found a thing called \"Gatecrasher\" which connected out of my computer using port 6969. I googled it, and it seems to be a trojan. It\'s trying to connect to this ip, 109.23...
157.55.199.236 - constant (for days) tcp probing
157.55.199.236 and 70.37.82.196 from port 12200 to various ports on destination computer sometimes a little as 6 minutes apart to 1 hour..averaging approx 30 minutes apart. Usually they probe port 27...
222.186.24.66 - alert
tried to connect to scvhost.exe. Malwarebytes stopped.tried to connect to scvhost.exe. Malwarebytes stopped.tried to connect to scvhost.exe. Malwarebytes stopped.tried to connect to scvhost.exe. Malwa...
64.111.211.172 - Google Redirecting and blocking of websites
My antivirus program Avast keeps blocking common sites like Photobucket, Imageshack, and yahoo!Answers saying that the website was blocked, and this IP address always comes up with it.
Why the **** ...
64.111.211.172 - Spam
SpaM am sick of this guy. Every website link i click on this thing keeps on popping up spam spam spam spam spam spam spam...
89.149.236.241 - computer attack
tryed to hack my computer several times but got stopped by firewall.would like to ban this ip address. not sure why it has to be 25 words but ok with it ...
64.111.211.172 - WebBrowswer Redirect
Occationally my web browser will redirect to the IP address 64.111.211.172 but then my antivirus blocks the connections. The error is reported as Inefection:URL: mal...
189.19.206.152 - how does facebook work
http://estirsa.com/images/41/live-granny-tube.html live granny tube, =-D, http://ogmfamily.com/widgets/82/busty-videos.html busty videos, =D, http://munder.org/.fp/064/sleep-disorders.html sleep dis...
189.19.206.152 - presbyterian hospital dallas
http://ogmfamily.com/widgets/82/hard-sex-tube.html hard sex tube, avdc, http://i2domain.com/plaincart/30/open-dns.html open dns, %-P, http://reddogpub.ca/assets/248/my-facebook.html my facebook, 69...
189.19.206.152 - alicia keys nude
http://chamberabbotsford.com/webalizer/812/sleazy-dream.html sleazy dream, 29507, http://just2getit.info/email/416/cooks-illustrated.html cooks illustrated, 242539, http://gymabbotsfordbc.com/images...
125.45.109.166,1 - Daily attacks from 125.45.109.166
My wireless router is reporting attacks from this address up to 20 times a day.
TCP Packet - Source:125.45.109.166,12200 Destination:82.26.192.123,3128 - [DOS] TCP Packet - Source:125.45.109.166,12...
189.19.206.152 - izod center
http://bcbusinessguide.com/_notes/471/god-life-apperal.html god life apperal, vhe, http://obamaiscommunist.com/aspnet_client/79/capitalism-is-right-wing.html capitalism is right wing, 411972, http:/...
189.19.206.152 - movies online
http://theconstitutionists.info/images/32/camp-songs.html camp songs, 8), http://theconstitutionists.com/cp/30/ciabatta-bread-recipe.html ciabatta bread recipe, 857, http://www.tug6.com/pollphp/21/i...
189.19.206.152 - huge d cups
http://crushingplant.info/Templates/544/hotels-in-las-vegas.html hotels in las vegas, bngom, http://crushingplant.info/Templates/544/safe-mail.html safe mail, =-PPP, http://blackdiamondgunclub.org/S...
189.19.206.152 - lolly art model
http://computerlearning.info/webalizer/455/elizabeth-smart.html elizabeth smart, 6505, http://office-x8.com/cp/829/safe-auto-insurance.html safe auto insurance, =PP, http://speakoutnow-america.org/c...
It dos a port scan, firewall workt well...
189.19.206.152 - continental united merger
http://whatsoutthere.com/music/619/centipedes-and-millipedes.html centipedes and millipedes, =-PPP, http://computerserviceabbotsford.com/images/448/free-nude-women-pics.html free nude women pics, %(...
68.94.156.1 - continues to hammer the firewall
INF 2010-09-26T14:51:39-05:00 named: dropped malicious resp from 68.94.156.1
INF 2010-09-26T16:26:56-05:00 named: Previous log entry repeated 117 times
this happen over 300 times......
68.42.208.145 - narrow range specific ports being targeted
INF 2010-09-28T19:29:53-05:00 fw,fwmon src=68.42.208.145 dst=76.251.32.175 ipprot=17
sport=1413 dport=1434
Unknown inbound session stopped...
12.194.142.133 - What is this computer been set to do?
INF 2010-09-28T18:48:57-05:00 fw,fwmon
src=12.194.142.133 dst=76.251.32.175 ipprot=17 sport=55700 dport=6066
Local Session, Packet Passed...
211.154.135.19 - Chinese seem want to harm AT&T
INF 2010-09-28T15:06:55-05:00 fw,fwmon src=211.154.135.19 dst=76.251.32.175 ipprot=6 sport=6000 dport=1433 Unknown inbound session stopped
What do these people want?...
76.191.96.151 - probable malware
INF 2010-09-28T14:54:05-05:00 fw,fwmon src=76.191.96.151 dst=76.251.32.175 ipprot=6 sport=12200 dport=8085 Unknown inbound session stopped
this could be malware but it\'s like the attacks from Chin...
222.236.44.115 - 222.236.44.115 incoming requests
I noticed a lot of blocked incoming requests from this IP 222.236.44.115 and did a whois,found this. What the hey?! Seriously, one IP address constantly trying for years?...
160.79.134.2 - Fin Scan
For last few hours, ever minute or so, I keep getting a Firewall Alert: Intrusion attempt detected: Fin Scan...
195.24.68.47 - unknown inbound session
attempted connect of unusual port range could be a bot net attack.
INF 2010-09-27T04:14:57-05:00 fw,fwmon src=195.24.68.47 dst=76.251.32.175 ipprot=6 sport=63105 dport=1080 Unknown inbound se...
58.218.204.110 - Attempt to enter my ip #
I keep getting the same IP number from this location. Thanks to my virus protection and firewall they can not enter. But If there is something can be done about this attempt to get into my computer pl...
71.52.255.163 - Unauthorized access to email account
This IP was snooping my email by gaining unauthorized access....
213.186.42.104 - looking for phpmyadmin ? go there: http://www.phpmyadmin.net/home_page/downloads.php
213.186.42.104 - - [15/Sep/2010:22:04:40 +0200] "GET //phpMyAdmin/ HTTP/1.1" 404 209
213.186.42.104 - - [15/Sep/2010:22:04:40 +0200] "GET // HTTP/1.1" 200 6524
213.186.42.104 - - [15/Sep/2010:22:04:...
195.2.255.227 - looking for phpmyadmin ? go there: http://www.phpmyadmin.net/home_page/downloads.php
195.2.255.227 - - [04/Sep/2010:10:02:54 +0200] "GET /phpmyadmin//scripts/setup.php HTTP/1.1" 404 227
195.2.255.227 - - [04/Sep/2010:10:03:24 +0200] "GET /phpmyadmin//setup/config.php?type=post HTTP/1...
217.22.60.14 - - [02/Sep/2010:16:15:14 +0200] "GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1" 404 239
217.22.60.14 - - [02/Sep/2010:16:15:15 +0200] "GET /scripts/setup.php HTTP/1.1" 404 215...
94.23.3.53 - - [01/Sep/2010:06:04:26 +0200] "HEAD http://62.12.178.149:80/mysql/admin/ HTTP/1.1" 404 -
94.23.3.53 - - [01/Sep/2010:06:04:26 +0200] "HEAD http://62.12.178.149:80/mysql/dbadmin/ HTTP/1....
61.184.136.164 - Maybe he is looking for a store while looking for install.txt ???
61.184.136.164 - - [29/Aug/2010:02:42:43 +0200] "GET HTTP/1.1 HTTP/1.1" 400 226
61.184.136.164 - - [29/Aug/2010:02:42:44 +0200] "GET /install.txt HTTP/1.1" 404 209
61.184.136.164 - - [29/Aug/2010:02...
82.53.42.224 - Scanning My Webserver
The ip has been scanning my webserver, stole all the information on my pc.. i need to get it off my pc.. help me pls...
93.67.54.72 - Network Attack
25/09/2010 5:45:43 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 93.67.54.72 to local port 1434 Absent
...
221.226.17.14 - 221.226.17.14 brute force ftp
Got a notification from my firewall that this IP address made 5 login-attempts within 5 minutes and has therefore been blocked... Who are they and what do they want?...
221.195.73.86 - Why doesn't anyone actually do something about this?
Fucking Chinese government allowing this to continue.
[INFO]Blocked incoming TCP connection request from 221.195.73.86:12200 to ***.***.***.***:1080
[INFO]Blocked incoming TCP connection request f...
159.153.226.50 - Systematic port scans, UDP
Electronic Arts, Inc. has been methodically and relentlessly scanning my computer for little over a month now. Every hour for about 45 minutes. Stopped for a few days and are now back at it again. ...
125.45.109.166,1 - 125.45.109.166,12200 is engaging in continual attack on ports
This IP has been continually attempting to hack into my computer for quite some time. I think they are using an autodialler and cycling thru' IP addresses. Reason I think this is that the times of att...
61.33.227.125 - Brute Force Attack on Asterisk Server
This IP is attempting to hack Asterisk servers. Got hit with a full dictionary attack plus some. ...
222.236.44.115 - Constant blocked attempts
My firewall log shows this and a few other related IPs attempting to access my pcs using the same ports continually for months....
23.09.2010 7:59:35 Intrusion.Win.MSSQL.worm.Helkern 96.11.198.52 UDP 1434
...
117.22.229.187 - netrwork attack
9/22/2010 4:39:44 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 117.22.229.187 to local port 1434
...
123.154.26.11 - 123.154.26.11
An unknown firewall is claiming the previous listed IP address is trying to access my computer etc. The firewall wants me to pay a fee to block the IP address....
123.154.26.11 - 123.154.26.11
An unknown firewall is claiming the previous listed IP address is trying to access my computer etc. The firewall wants me to pay a fee to block the IP address....
58.218.204.110 - port scancs
Your computer\'s TCP ports:
9000, 8000, 2301, and 8088 have been scanned from 58.218.204.110.....
This non legitimate IP address tried to get into my personal computer by pretending to be a part of Msn Messenger's Staff when indeed the following ip address is not related to microsoft how it claime...
219.149.194.245 - netrwork attack
9/18/2010 10:50:46 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 219.149.194.245 to local port 1434...
61.142.12.86 - Network attack Intrusion.Win.MSSQL.worm.Helkern
received log in kaspersky stating this attacker from UDP port 1434...
141.85.32.132 - Detected: Intrusion.Win.MSSQL.worm.Helkern
9/16/2010 7:27:12 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 141.85.32.132 to local port 1434
Absent
...
220.178.37.210 - Detected: Intrusion.Win.MSSQL.worm.Helkern
9/16/2010 10:44:56 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 220.178.37.210 to local port 1434 Absent
...
67.91.86.178 - Nmap TCP scan
As reported by Charter Security Suite:
Description: Intrusion attempt detected: Nmap TCP scan
Action: Firewall has blocked this traffic
Time: 9/13/2010 5:24:12
Direction: Inbound
Protocol: tcp
...
207.99.91.2 - Nmap TCP scan
As reported by Charter Security Suite:
Description: Intrusion attempt detected: Nmap TCP scan
Action: Firewall has blocked this traffic
Time: 9/13/2010 5:45:49 PM
Direction: Inbound
Protocol: t...
221.192.199.51 - Found attack
Found attack from 221.192.199.51 in port 7212 => Mon Sep 13 09:00:42 2010
Found attack from 221.192.199.51 in port 8080 => Mon Sep 13 09:00:42 2010
Found attack from 221.192.199.51 in port 8000 ...
216.151.153.127 - Constant port scans.
Scanning my ports (and I hope nothing else) constantly, logged over a four-day period....
74.6.22.105 - IP: 128.154.26.11
I have the same problem as everybody else, why isn't there anyone answering this questions?
I'm also getting the alert of the IP-adress: 128.154.26.11
Please answer,
thanx...
220.178.37.210 - Detected: Intrusion.Win.MSSQL.worm.Helkern
9/12/2010 2:07:54 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 220.178.37.210 to local port 1434 Absent
...
218.30.22.82 - Detected: Intrusion.Win.MSSQL.worm.Helkern
9/12/2010 12:33:43 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.30.22.82 to local port 1434 Absent
...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
9/12/2010 10:31:28 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1434 Absent
...
61.128.110.96 - Detected: Intrusion.Win.MSSQL.worm.Helkern
9/11/2010 11:41:20 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434 Absent
...
61.106.124.15 - Network attack intrusion from this IP
this IP attempts to attack my computer almost every day....
58.218.204.110 - 58.218.204.110 port scan
How can this be stopped for good ? can this ip be blocked? not only by my firewall...
91.212.226.179 - Constant attack
Addresses in subnet 92.212.226.* are constantly trying to attack my network....
61.128.110.96 - AGAIN : Detected: Intrusion.Win.MSSQL.worm.Helkern
9/7/2010 11:12:42 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434 Absent
...
91.216.73.59 - Hacker - Needs to be arrested.
Hacker....Keeps trying to hack.
Located in Eupore
91.216.73.59...
91.188.60.21 - try to atack me every 10 min
this ip adres try to atack me every 10min one time my virus scan can't stop it there was a fake virusscanner and it blocks almost everything what you can do to delete it whit the protection tool...
141.85.32.132 - Detected: Intrusion.Win.MSSQL.worm.Helkern
9/6/2010 5:43:53 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 141.85.32.132 to local port 1434 Absent
...
61.128.110.96 - network attack
network attack detected:intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.128.110.96 to local port 1434...
208.68.139.89 - mulitple attacks from this address
Symantec keeps popping up with attacks from this address.
Keeps blocking him....
91.188.60.21 - mulitple attacks from this address
Symantec keeps popping up with attacks from this address.
Keeps blocking him....
221.192.199.48 - Won't stop!!!
Found attack from 221.192.199.48.
Source port is 12200 and destination port is 8085 which use the TCP protocol.
Thu Sep 2 16:11:51 2010
=>Found attack from 221.192.199.48.
Source port is 12200...
Thu Sep 2 08:33:16 2010 =>Found attack from 125.45.109.166. Source port is 12200 and destination port is 8085 which use the TCP protocol. Thu Sep 2 08:33:16 2010 =>Found attack from 125.45.109.166. So...
58.218.204.110 - port scan
Thu Sep 2 07:38:38 2010
=>Found attack from 58.218.204.110.
Source port is 12200 and destination port is 8085 which use the TCP protocol.
Thu Sep 2 07:38:38 2010
=>Found attack from 58.218.204...
221.192.199.48 - port scan
Thu Sep 2 07:38:38 2010
=>Found attack from 58.218.204.110.
Source port is 12200 and destination port is 8085 which use the TCP protocol.
Thu Sep 2 07:38:38 2010
=>Found attack from 58.218.204...
62.84.18.15 - port scan
Found attack from 62.84.18.15.
Source port is 4064 and destination port is 18457 which use the TCP protocol.
Thu Sep 2 08:21:52 2010
...
218.151.123.93 - port scan Seoul, Korea, Republic Of
Found attack from 218.151.123.93.
Use the ICMP protocol.
Thu Sep 2 08:04:15 2010
=>Found attack from 218.151.123.93.
Use the ICMP protocol.
Thu Sep 2 08:05:15 2010
...
221.192.199.48 - curity
I have reported them to US-CERT, IP Joint Task force security in the UK (But there useless to us) seems that US-CERT doesn\'t care, I have issued many iptables drops on there subnets, example..
# ip...
68.54.68.52 - Constant Connection Attempt
My antivirus program detects connection attempts from this IP (Port 137) every minute when I\'m online. The actual location of that computer is very close to my house and that scares me....
221.192.199.46 - Found Attack
Found attack from 221.192.199.48.
Source port is 12200 and destination port is 8085 which use the TCP protocol.
Happens ever 4-5 minutes and causes internet to disconnect for about 5 minutes...
70.30.108.158 - IP 70.120.78.80 unauthorized access to ports
Attempting unauthorized access through ports...
202.28.186.3 - Tried to access private website by password guessing
Tried to access private website by password guessing using the unknown user name abby. Fri 2010/08/28...
71.158.182.166 - Alert - Intrusion Prevention - Possible port scan detected
08/26/2010 08:33:09.288 - Alert - Intrusion Prevention - Possible port scan detected - 71.158.182.166, 52044, WAN - 204.0.75.2, 16411, WAN - UDP scanned port list, 53819, 16407, 164...
58.218.204.110 - constant ports scans
Works alone or in cooperation with other Chinese unofficial low-tech intelligence gathering offices. If anyone still believes that this IP is hiding a geek in search of porn site, think again. No one ...
218.75.79.18 - attempted ssh attack
above ip address attempted to connect on ssh port (blocked by firewall destination IP rule)...
Yesterday around 6:32 central a user from this address attempted to log into our server with the username manager over the source port 3602. Access was denied due to lack of credentials. I verified ...
122.225.100.154 - Again !! Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 122.225.100.154
8/24/2010 6:00:17 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 122.225.100.154 to local port 1434...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern UDP
8/24/2010 3:01:28 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1434 Absent
...
41.234.235.218 - Kaspersky detected attack from 122.225.100.154 multi
Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1434...
117.200.130.189 - TCP Dcom trace
my system is getting attack from 117.200.100.120
and also getting attack from this ip
117.230.130.189
getting the same dcom port attack tcp
alert is send by my firewall....
117.200.130.189 - TCP Dcom trace
my system is getting attack from 117.200.130.189
and also getting attack from this ip
117.200.100.120
getting the same dcom port attack tcp
alert is send by my firewall.
...
216.245.205.74 - judge.php attemtpt to connect to my server, action not autorized.
Server logs tripped on this access
GET 'http://216.245.205.74/judge.php'
HDR: 'User-Agent' = 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)'
HDR: 'Accept' = '*/*'
HDR: 'Host' = '216....
61.61.20.132 - 61.61.20.132 repeated intrusion attempts
has been attempting to intrude repeatedly for days...
58.60.10.10 - 74 attempts on port 9415 over one month
74 attempts on port 9415 over one month according to snort and BASE report.
namp scan revealed a machine with port 80 open (probably for trapping users)
...
61.128.110.96 - network attack intrusion
18.Aug.2010 1:48:44 AM Unknown Denied: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434
...
211.143.198.2 - firewall alert from 211.143.198.2
18.Aug.2010 1:48:44 AM Unknown Denied: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434
...
61.61.20.132 - intrusion attempt blocked by my Norton software
I keep getting reports from my norton software that this ip is trying to attack me....
91.216.73.59 - intrusion attempt blocked by my Norton software
I keep getting reports from my norton software that this ip is trying to attack me....
61.61.20.135 - Attacks from 61.61.20.135 (nyewrika.in)
Norton Internet security suite blocks dozens of intrusion attempts from this IP address daily. It began in June and Keep up until now. Please someone stop this mf....
94.179.56.151 - constant attacks
94.179.56.151 is traced to:
Kiev, Ukraine
Constant attacks to try and spam...
61.61.20.135 - Frequent attacks
I've been getting notices from Norton 360 that it's blocking attacks. It happens every minute or so. It's been from IP`S 61.61.20.132/135, 68b6b6b6.com, 91.216.73.59, 91jjak4555j.com, 109.236.81.40, 9...
91.212.226.7 - IP address attempting to port scan my computer
There's an IP address which is constantly attempting port scans on my computer. BitDefender keeps blocking it, but I'd like to get back at them. I found their address which is located in China. Anyone...
117.121.249.253 - this IP always send me CHAT AIM 5.5 login attempt
My router is logging CHAT AIM 5.5 login attempt from this ip address. It is affecting my bandwidth/performance....
58.218.204.110 - Malicious port scan attack
Several times a day this site is trying to gain access to my system. Firewall stops it each time but this needs to stop...
92.0.102.37:6535 - this IP address is attempting to stealth mode log on
I do not recognize this IP address attempting to stealth log on...
129.82.138.38 - Firewall blocked IP-Adress
Firewall blocked IP-Adress 129.82.138.38 ICMP-Protocol "traffic filtering"
...
218.22.244.45 - Detected: Intrusion.Win.MSSQL.worm.Helkern
8/9/2010 3:02:18 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434 Absent
...
184.84.255.24 - pinging my firestarter firewall
a 184.84.255.24 deploy.akamaitechnologies.com
is the exact source identification given under firstarter.
Why is this address coming thru my paid dsl service at all? I've noticed increase virus de...
10.0.10.13 - Maliscious e-mails with Trojans
***PLEASE DO NOT REPLY TO THIS MESSAGE***
Dear my e-mail address
Thank you for your online payment of $500.00. Your payment will be applied on Sat, 7 Aug 2010 02:24:44 +1000
Remember you can ...
202.102.234.71 - Port Scan Attack
Your computer's TCP ports:
9415, 9090, 2479, and 73 have been scanned from 202.102.234.71.....
222.45.112.59 - severe port scanning from 218.10.111.119
every day several port scan from 218.10.111.119. please help...
Gateway Anti-Virus Alert: Suspicious#bredolab_4 (Trojan) blocked - 98.213.45.66...
60.242.221.10 - Attempting access system remotely using RDP Protocol
Hack attempt on TCP port 3389...
61.61.20.135 - Multiple intrusion attempts
Norton Internet security suite blocks dozens of intrusion attempts from this IP address daily...
A window pop-up and then it makes my pc hanged. my anti-virus detected it and stated the IP address. The attacker stays in Yahoo Chat> Regional> Philippines> Philippine Room #12. They are many. Unt...
61.128.110.96 - Network Attack Intrusion
30 July 2010 2:26:29 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 Detected by Kaspersky software. Apparently this attack was intended to glean info from my computer or to take...
61.128.110.96 - Network Attack Intrusion
30 July 2010 2:26:29 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96...
211.142.25.38 - 7/29/2010 9:10:58 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 211.142.25.38 to local port 1434 A
This schmo is constantly trying to access my firewall...pls ban this IP address!...
91.212.226.67 - tidserv request from Trojan to this IP
Request also to 85.12.46.155, 158, and several others. SAV 10 does not stop it, but SEP11 does. Appearance of infected files in C:\\windows\\ and D&S stopped after IP was blocked....
74.125.157.99 - EXPLOIT Microsoft Color Management Module Buffer Overflow.
I have about 30 Firewall alerts all from G oogle addresses saying this:
EXPLOIT Microsoft Color Management Module Buffer Overflow
The other IPs:
72.14.253.136
74.125.157.99
74.200.247.35
7...
74.125.157.99 - EXPLOIT Microsoft Color Management Module Buffer Overflow.
I have about 30 Firewall alerts all from G oogle addresses saying this:
EXPLOIT Microsoft Color Management Module Buffer Overflow
The other IPs:
72.14.253.136
74.125.157.99
74.200.247.35
7...
194.79.21.146 - Repeatedly attempting to connect remotely
IP is repeatedly attempting to connect to my firewall. Attempts repeat every 5 seconds and have continued for nearly 24 hours....
94.179.25.234 - Repeatedly attempting to connect remotely
IP is repeatedly attempting to connect to my firewall. Attempts repeat every 5 seconds and have continued for nearly 24 hours....
114.178.170.72 - Repeatedly attempting to connect remotely
IP is repeatedly attempting to connect to my firewall. Attempts repeat every 5 seconds and have continued for nearly 24 hours....
88.135.132.58 - Repeatedly attempting to connect remotely
IP is repeatedly attempting to connect to my firewall. Attempts repeat every 5 seconds and have continued for nearly 24 hours....
211.142.25.38 - This guy want to hack me
my firewall alert when this guy wanna go into my commputer...
91.212.226.7 - An attack came from this IP Address
My Norton Anti-Virus blocked an attack from this address today, it blocked several attacks, this one being the fairly recent....
61.61.20.132 - An attack came from this IP Address
My Norton Anti-Virus blocked an attack from this address today, it blocked several attacks, this one being the fairly recent....
61.61.20.135 - An attack came from this IP Address
My Norton Anti-Virus blocked an attack from this address today, it blocked several attacks, this one being the most recent. Probably shouldn't have use their IP Address as their identity....
213.163.69.106 - An attack came from this IP Address
My Norton Anti-Virus blocked an attack from this address today, it blocked several attacks, this one being the most recent....
91.212.226.59 - Constant Firewall Attack
i get attacked about 50 times a day by this. I belive i was infected before but now all is clean and they just keep trying and trying....
125.45.109.166 - Multiple Port Scans Also
Address has been actively scanning me for at least 3 weeks. Firewall logged 41 attacks this weekend from this address. Last attack was today @ 1:46pm.
7/26/2010 13:46:43.544 Alert Intrusion Preve...
61.235.46.146 - Network attack intrusion!
Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 and 122.225.100.154 to local port 1434....
91.212.226.59 - Trying to access my computer / Intrusion attempts
91.212.226.59 Intrusion attempt(s). Constant attacks, Norton alerts every few minutes - severity \'high\' - just will not stop attacking my computer! Same problems as mentioned many times above....
113.133.129.44 - Intrusion
17-07-2010 12:54:36 Detectadas: Intrusion.Win.MSSQL.worm.Helkern UDP de 113.133.129.44 para porta local 1434...
219.150.223.253 - Intrusion
23-07-2010 23:45:14 Detectadas: Intrusion.Win.MSSQL.worm.Helkern UDP de 219.150.223.253 para porta local 1434...
118.213.78.20 - Intrusion
24-07-2010 8:32:53 Detectadas: Intrusion.Win.MSSQL.worm.Helkern UDP de 118.213.78.20 para porta local 1434...
67.83.179.143 - Intrusion
24-07-2010 10:43:19 Detectadas: Intrusion.Win.MSSQL.worm.Helkern UDP de 67.83.179.143 para porta local 1434 ...
200.35.176.225 - A new bot being sent out to attack the global village.
It may be burgeoning new hacker, but I am pretty sure that it is probably some poor neglected pc that has recently been infected and is now being sent out to attack other computers.
...
61.128.110.96 - Network Attack Intrusion
7/23/2010 14:10:36 Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434...
61.128.110.96 - I got this alert of intrusion
22-07-2010 18:15:43 Unknown Network Attack Blocker Denied: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434...
IPS 82.12.46.155 has made numerous attempts to access my computer over the past few months - all attempts have so far been blocked by Norton...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.150.223.253, 122.225.100.154, 219.149.194.245,61.128.110.96
Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.150.223.253, 122.225.100.154, 219.149.194.245,61.128.110.96 every couple of hours...
66.91.249.47 - UDP scan
Your computer\'s UDP ports:
53694, 1434, 53, and 111 have been scanned from 66.91.249.47..
Spoke too soon, always that it was China, now the US...
74.125.106.38 - CHAT QQ&TM Login attempt via TCP -1
At 2010-07-21 04:29:04, my Cisco RVS4000 logged "CHAT QQ&TM Login attempt via TCP -1" from 74.125.106.38. At that hour, no one is online. ...
137.134.240.49 - 7 attempts to access my computer from ip 85.12.46.155.80
Over the course of approximately 4 hours 85.12.46.155 attempted to access my computer on 7 occasions - the same IP previously attempted to access my computer - attempts reported by Norton 360...
58.218.204.110 - TCP Port scans
Your computer's TCP ports:
9415, 3246, 2479, and 8000 have been scanned from 58.218.204.110.
Another from China.... why does no on one else in the world do it, always China!...
219.150.223.253 - Network Attack Intrusion
7/21/2010 12:21:00 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.150.223.253 to local port 1434...
61.128.110.96 - Network Attack Intrusion
7/21/2010 12:27:11 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434...
91.212.226.59 - 91.212.226.179:80
It keeps being blocked by my anti-virus every 10 minutes or so... :( Help!...
58.218.204.110 - Searching for proxy
kernel: Firewall: *TCP_IN Blocked* IN=venet0 OUT= MAC= SRC=58.218.204.110 DST=208.89.214.200 LEN=40 TOS=0x00 PREC=0x00 TTL=111 ID=256 DF PROTO=TCP SPT=12200 DPT=8080 WINDOW=8192 RES=0x00 SYN URGP=0
...
109.173.55.10 - Connection attempt blocked by Firewall
When my firewall blocked this address it said:
IP/TCP/UDP packets with headers with inconsistent data
also on another line:
Packets with incorrect SYN, ACK and FIN combinations
I don\\\'t kn...
87.106.241.171 - Connection attempt blocked by Firewall
When my firewall blocked this address it said:
TCP connection attempt blocked.
I don't know what this means, but I've been getting more and more of these attempts from different sources....
79.172.195.57 - intrusion generic TCP flags bad combine attack
Firelwall Alert.
Network Attack intrusion generic TCP flags bad combine attack...
122.225.100.154 - Network Attack Intrusion
15-07-2010 23:29:58 Detectadas: Intrusion.Win.MSSQL.worm.Helkern . UDP de 122.225.100.154 para porta local 1434...
91.212.226.59 - trying to access computer
Finally removed Antivir Solution Pro fraud virus. IP Address 91.212.226.59 continues to try and access our system....
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1430
Constant attacks and alerts via Kaspersky from this IP...always when either on gaming site or in-game...
219.149.194.245 - Detected: Intrusion.Win.MSSQL.worm.Helkern
7/14/2010 10:36:28 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.149.194.245 to local port 1434 Absent...
58.218.204.110 - TCP scans
Your computer\'s TCP ports:
8085, 9000, 1080, and 9090 have been scanned from 58.218.204.110..
Why is it always the Chinese?...
58.218.204.110 - TCP scans
Your computer's TCP ports:
8085, 9000, 1080, and 9090 have been scanned from 58.218.204.110..
Why is it always the Chinese?...
MSSQL.worm.Helkern UDP from 61.128.110.96 attacks my computer (guarded by Kaspersky) on a daily basis...says addr. is spoofed, but blocked luckily. ...
118.213.78.20 - Network Attack Intrusion
Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 118.213.78.20 to local port 1434
10/07/2010 06:02pm in tim of suadi arabia...
61.128.110.96 - Detected: Intrusion.Win.MSSQL.worm.Helkern
7/8/2010 12:24:05 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434 Absent
...
This IP keeps popping up and my firewall keeps blocking it.
...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
7/5/2010 2:49:04 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1434 Absent
...
91.212.226.59 - track him (them) down abuse@netdedicated.ru
91.212.226.216 Location Information
Gornaya st.
More information ...
Inetnum: 91.212.226.0 - 91.212.226.255
Netname: ZHIRK
Descr: Artem Zhirkov Alekseevich
Country: RU
Org: ORG-ZA44-RIPE
A...
219.150.223.253 - Detected: Intrusion.Win.MSSQL.worm.Helkern
7/3/2010 12:02:54 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.150.223.253 to local port 1434 Absent
...
125.45.109.166,1 - port scan by 125.45.109.166
Thu 2010-06-24 21:29:40 TCP flood From 125.45.109.166 port:12200 To 81.58.132.88 port:808 droped
Thu 2010-06-24 21:29:40 TCP flood From 125.45.109.166 port:12200 To 81.58.132.88 port:50050 droped
Th...
125.45.109.166,1 - port scan by 125.45.109.166
Thu 2010-06-24 21:29:40 TCP flood From 125.45.109.166 port:12200 To 81.58.132.88 port:808 droped
Thu 2010-06-24 21:29:40 TCP flood From 125.45.109.166 port:12200 To 81.58.132.88 port:50050 droped
Th...
221.195.73.68 - TC port scans 221.195.73.68
8085, 9415, 3246, and 3128 have been scanned from 221.195.73.68..
These ports was scanned continually yesterday, three or four times an hour!...
124.121.36.117 - 124.121.36.117 Nonthaburi Thailand
this ip is hitting my firewall several times on port 26649...trying to hack me no success....asshole !!!!...
89.248.172.172 - Also getting hits on malwarebyes
this morning suddenly started getting many many hits on malwarebytes from this IP :(...
202.102.234.71 - Syncflood attack from 202.102.234.71
firewall reported syncflood attack from 202.102.234.71...
91.212.226.59 - An Intrusion attempt by 91.212.226.59 was blocked.
Norton Security blocked an Intrusion attempt. \\\\\\\"Network traffic from 91.212.226.59 matches the signature path of a known attack....
221.130.140.18 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/30/2010 11:51:59 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 221.130.140.18 to local port 1434 Absent...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/29/2010 12:46:35 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 122.225.100.154 to local port 1434
...
221.195.73.68 - Constant TCP connection requests
This turkey just doesn't let up. Constantly requesting TCP connection to multiple ports every day, which is being denied by the router....
81.92.156.112 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/28/2010 1:35:09 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 81.92.156.112 to local port 1434 Absent...
Alerted Juniper today and last week of FIN bit but no ACK bit in return; in an attempt of DDOS attack and/or network scan. Today this occurred 10 times in a row each 1 time. The first time, last wee...
85.12.46.158 - Attacking Computer
Keeps attacking and trying to access my computer; Norton keeps blocking it. Says it\'s rooted from programfiles/.../Mozilla.exe but I assume that is because I was using that browser not because it is ...
202.102.234.71 - TCP scans from 202.102.234.71..
I have been scanned 8 times in the last two hours.
Somebody is scanning your computer.
Your computer's TCP ports:
8085, 9415, 9090, and 8090 have been scanned from 202.102.234.71..
Isn't the...
219.150.223.253 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/28/2010 3:35:24 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 219.150.223.253 to local port 1434...
61.235.46.146 - Network Attack intrusion
27/06/2010 06:04:36 pm Intrusion.Win.MSSQL.worm.Helkern
UDP from 61.235.46.146 to local port 1434
...
211.143.230.140 - Network Attack intrusion
27/06/2010 03:16:07 am Intrusion.Win.MSSQL.worm.Helkern
UDP from 211.143.230.140 to local port 1434
...
219.150.223.253 - Network Attack intrusion
27/06/2010 04:07:43 ص
Intrusion.Win.MSSQL.worm.Helkern UDP from 219.150.223.253 to local port 1434
...
78.138.169.168 - the person is sending worms
he/she is from china,the ip adress is 211.143.230.140 and the person is sending worms to my computer...
78.138.169.168 - the person is sending worms
he/she is from china,the ip adress is 211.143.230.140 and the person is sending worms to my computer...
67.152.1.231 - MOYARI13
From Outpost Security Suite 7 log
12:45:18 67.152.1.231 Узел заблокиÑован на 5 мин. MOYARI13...
81.92.156.112 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/26/2010 1:43:32 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 81.92.156.112 to local port 1434
...
202.102.234.71 - and another ...TCP scans from 221.195.73.68
Your computer\'s TCP ports:
9415, 2479, 9000, and 3128 have been scanned from 202.102.234.71
Sure are keeping my firewall busy today...
221.195.73.68 - TCP scans from 221.195.73.68
Your computer\'s TCP ports:
3246, 8090, 1080, and 7212 have been scanned from ....
202.102.234.71 - Port Scanning
Another port scanner --- from where? CHINA of course! 202.102.234.71 requests multiple TCP connections all blocked by the router....
85.12.46.158 - Constantly attacking my computer
Keeps attempting to attack my computer but my Norton is blocking it with its firewall....
219.150.223.253 - Network attack intrusion win.mssql.worm.helkern
6/23/2010 2:24:43 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.150.223.253 to local port 1434...
92.237.42.252 - intrusion.generic.tcp.flags.bad.combine.attack
intrusion.generic.tcp.flags.bad.combine.attack...
85.12.46.158 - Constant alerts from ESET on this IP address
Seems to be attacking at least some of my searches and redirecting them....
202.103.9.51 - ataque de red de 218.30.22.82! >:(
hola a todos soy de chile y kaspersky internet security 2010, me adetectado un ataque de red de un ip 218.30.22.82.(china) y de otros similares. ok saludos paz. espero que esto se pueda denunciar....
91.212.226.59 - This IP is constantly attacking my Firewall
My Norton I.S. is showing me that approx every 10 minutes it is blocking an intrusion attempt: 6/17/2010 7:57 PM,High,"An intrusion attempt by 91.212.226.59 was blocked. Application path (less than) p...
137.134.240.49 - 4 attempts to 'access' my computer from ip 85.12.46.155
Over a period of approximately 10 minutes 4 attempts were made to 'access' my computer from ip address 85.12.46.155. Norto 360 reported intrusion attempts and provided a very long URL that started 7qa...
218.30.22.82 - Intrusion attempt
2010/06/19 05:46:39 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.30.22.82 to local port 1434...
66.35.46.194 - Intrusion attempts
Interesting that these connection attempts from these ip's began just after I was browsing the DShield site, which is in the same ip range....
66.35.46.194 - Intrusion attempts
66.35.46.193 just got into the act as well, trying to connect to my port 33435. So now I've got 66.35.46.193 trying to connect to 33435 while 66.35.46.194 and 66.35.46.195 both try to connect to 33436...
66.35.46.194 - Intrusion attempts
66.35.46.194 and 66.35.46.195 both attempted to make TCP connections to my ports 33436 and 33437 several times. Connections originated first from remote port 10545, then 11308, then 11944, then 10598....
211.147.251.21 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/18/2010 12:39:43 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 211.147.251.21 to local port 1434...
213.120.161.139 - riding in on free download
location west of harrogate uk - RAF menwith hill? area...
137.134.240.49 - Intrusion attempt
Two TCP connection attempts were made from this ip's port 50204 to my port 21. Both were blocked by firewall. First time I've seen this ip show up in my logs....
211.139.255.29 - Intrusion Attempt
2010/06/16 05:26:18 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 211.139.255.29 to local port 1434...
218.16.143.93 - Intrusion attempt
TCP connection attempt from this ip from remote port 12647 to my port 22. Blocked by firewall. ...
222.208.183.218 - Intrusion attempt
TCP connection attempt from this ip from remote port 12200 to my port 8000. Blocked by firewall. All these Chinese ip's always seem to attack from port 12200. Makes it more obvious this is government ...
59.178.182.194 - Intrusion attempt
TCP connection attempt from this ip from remote port 50388 to my port 34782. Blocked by firewall. ...
122.227.164.71 - Intrusion attempt
TCP connection attempts from this ip from remote port 12200 to my ports 7212 and 8000. Blocked by firewall. Do any of these Chinese ip's ever use any port other than 12200 for this kind of crap? Makes...
221.195.73.86 - Intrusion attempt
TCP connection attempt from this ip from remote port 12200 to my port 8000. Blocked by firewall. Do any of these Chinese ip's ever use any port other than 12200? Seems I always get hit from that port,...
221.192.199.35 - Intrusion attempt
Three TCP connection attempts from this ip from remote port 12200 to my ports 80, 8000. and 7212. Blocked by firewall. Seems like all these Chinese ip's like to use their port 12200 to do this crap. I...
61.183.15.9 - Intrusion attempt
Two TCP connection attempts from this ip from remote port 12200 to my ports 80 and 8080. Blocked by firewall. Seems like all these Chinese ip's like to use their port 12200 for these shenanigans. At l...
58.53.128.61 - Intrusion attempt
Two TCP connection attempts from this ip from remote port 12200 to my ports 7212 and 8000. Blocked by firewall. Seems like all these Chinese ip's like to use their port 12200 for these shenanigans....
87.23.233.161 - Intrusion attempt
TCP connection attempt from this ip from remote port 2572 to my port 26432. Blocked by firewall....
61.136.78.113 - Intrusion attempt
TCP connection attempt from this ip from remote port 34468 to my port 22. Blocked by firewall....
91.212.226.59 - This IP constantly attacking my Firewall
Attacks every few minutes. Blocked by Norton AV...
61.128.110.96 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/15/2010 2:51:19 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434 Absent
...
222.162.143.19 - port scans
Jun 14, 2010 13:09:13.453 UTC - (TCP) 222.162.143.19 : 6000 >>> xxx.xxx.xxx.xxx (Texas) : 8080 - HTTP Proxy Scan
Jun 14, 2010 13:09:11.937 UTC - (TCP) 222.162.143.19 : 6000 >>> xxx.xxx.xx...
93.70.70.190 - port scanning
1 of many IP addresses from Italy probing my router all day the last 2 days....
221.192.199.48 - Port scan udp floods tcp floods arp icmp attacks
Port scan udp floods tcp floods arp icmp attacks Blocked incoming TCP connection request from 221.192.199.48:12200 to...
221.192.199.48 - Port scan udp floods tcp floods arp icmp attacks
Port scan udp floods tcp floods arp icmp attacks Blocked incoming TCP connection request from 221.192.199.48:12200 to ...
60.161.78.155 - Intrusion.Win.MSSQL.worm.Helkern ip:60.161.78.155
Intrusion.Win.MSSQL.worm.Helkern ip:60.161.78.155...
218.30.22.82 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/12/2010 11:14:24 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.30.22.82 to local port 1434 Absent
...
124.40.51.150 - Comodo firewall alerted to computer trying to connect
Application - C:Windows\System32\svchost.exe
Action - Blocked
Protocol - UDP
Source IP - 124.40.51.143
Source Port - 3***
Destination Port - 5****
Date - June 11th 2010 2:45AM
...
74.6.22.105 - This is a virus from 128.154.26.11
Not sure what is going on with this computer but I am constantly getting a popup screen that states "Warning! Identity theft attempt detected" Right underneath the red banner it says. "Hidden connecti...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/10/2010 3:42:21 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 122.225.100.154 to local port 1434
...
91.212.226.67 - This IP is constantly attacking my Firewall
Every 10 minutes this IP automatically attemps to hack into my hard drive. Symantec blocks it everytime, but I\'m disturbed to know that this IP is constantly trying to get in. Norton tells me that th...
91.212.226.59 - This IP is constantly attacking my Firewall
Every 10 minutes this IP automatically attemps to hack into my hard drive. Symantec blocks it everytime, but I'm disturbed to know that this IP is constantly trying to get in. Norton tells me that thi...
76.90.206.195 - Remote connection atempt
i received a remote connection attempt from ip address 76.90.206.195, i am not sure if it was a hacking attempt because i regected the request, i was refreshing my google mail account when i received ...
9.6.2010 15:45:5 - slow internet
While surfing the Internet comes to traffic congestion and difficult, and also to the strange behavior of the computer ...
9.6.2010 15:45:5 - slowing internet and software on my ps
While surfing the Internet comes to traffic congestion and difficult, and also to the strange behavior of the computer...
202.103.9.51 - intrusion.Win.MSSQL.worm.Hellkern:UDP
Hello from Germany...
Everyday says my Kaspersky that i have a Problem with this adress....
Sorry my englich iss not good!
I see that more People around the world this Problem have!
Its not funny....
222.45.112.59 - Unsolicited Port Scan 9415, 3246, 1080, and 8090
See this IP hit my firewall every five hours like clockwork....
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/5/2010 4:27:49 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 122.225.100.154 to local port 1434...
61.128.110.96 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/5/2010 2:25:13 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.128.110.96 to local port 1434
...
88.2.4.27 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/4/2010 11:31:12 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 88.2.4.27 to local port 1434 Absent
...
219.149.194.245 - network attack
03.06.2010 19:39:03 Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.235.46.146 to local port 1434...
219.149.194.245 - network attack
03.06.2010 19:39:03 Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.235.46.146 to local port 1434...
219.149.194.245 - network attack
03.06.2010 21:18:25 Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 219.149.194.245 to local port 1434
...
61.128.110.96 - Detected: Intrusion.Win.MSSQL.worm.Helkern
6/2/2010 1:35:58 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434 Absent...
4.179.142.206 - repeated attempts to log into my router
My router security log is reporting continual blocked attempts at remote administration from this IP address....
How can I get this IP address from trying to hack into my pc?...
76.111.199.206 - Detected: Intrusion.Win.MSSQL.worm.Helkern
5/29/2010 4:37:07 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 76.111.199.206 to local port 1434
...
218.30.22.82 - Intrusion.Win.MSSQL.worm.Helkern
2010/05/29 07:21:24 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.30.22.82 to local port 1434...
61.128.110.96 - Intrusion.Win.MSSQL
intrusion.Win.MSSQL.worm.Helkern UDP from 61.128.110.96 to local port 1434 ...
122.225.100.154 - Worm.Helkern
could kaspersky be behind this too? I mean some antivirus producers also provide viruses for them to gain from it. So far I was alerted by my kaspersky too. And so far all other complains are through ...
218.30.22.82 - Intrusion.Win.MSSQL.worm.Helkern
2010/05/28 07:35:47 ب.ظ Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.30.22.82 to local port 1434...
87.224.223.190 - Intrusion.Win.MSSQL.worm.Helkern
2010/05/28 07:34:11 ب.ظ Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 87.224.223.190 to local port 1434...
219.150.223.253 - Detected: Intrusion.Win.MSSQL.worm.Helkern
5/28/2010 4:08:28 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 219.150.223.253 to local port 1434...
60.161.78.155 - I am attacked daily!
I am attacked daily by the same IP. Why that IP isn't banned????????...
117.204.166.48 - Src IP session limit! From 117.204.166.48
We are getting continuous hits from IP 117.204.166.48. This is belongs to BNSL Network India. And also getting different IPs from the same subnet 117.204.0.0/16
and 117.199.0.0/16....
91.212.127.100 - 91.212.127.100 QUERY_STRING_UNESCAPED=
Vizitatorul numarul 39 de la IP-ul 91.212.127.100 cu numele Luni 24 Mai 2010 ora locala a clientului 2:13:46
Adresa client: 91.212.127.100
Nume server: allrequestsallowed.com
Browser c...
87.224.223.190 - Intrusion.Win.MSSQL.worm.Helkern UDP
ooiinef pihdc øppias oias c æouS CÃOuB OIHSC -BJ ssdv ooisnvn ...
190.2.29.193 - Intrusion.Win.MSSQL.worm.Helkern
2010/05/25 07:18:50 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 190.2.29.193 to local port 1434...
118.213.78.20 - Intrusion.Win.MSSQL.worm.Helkern
2010/05/25 06:41:53 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 118.213.78.20 to local port 1434...
128.154.26.11 - hidden connection IP 128.154.26.11
just installed Itunes on a new to me ( clean wiped) PC , second day I get this stuff???????, any thoughts on this?...
81.66.160.15 - MailEnable SMTP Request.Format.String
Is was an attempt to exploit the mail server....
128.154.26.11 - i dentity theft detected / trogen/ virise
opened a website in google and instantly inserted virises....
190.2.29.193 - Detected: Intrusion.Win.MSSQL.worm.Helkern
2010/05/23 06:25:37 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 190.2.29.193 to local port 1434...
221.130.140.18 - Detected: Intrusion.Win.MSSQL.worm.Helkern
2010/05/23 06:25:02 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 221.130.140.18 to local port 1434...
61.128.110.96 - Detected: Intrusion.Win.MSSQL.worm.Helkern
2010/05/23 06:10:04 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.128.110.96 to local port 1434...
74.6.22.105 - Virus from IP 128.154.26.11
IP address 128.154.26.11 keeps keeps giving a message that this IP is logged on to my computer. The message has a button to prevent attack then a sales page to buy the cleanup antivirus program. The F...
221.192.199.48 - since 3 month
inbound packets from this kid, 150 times/day !
in france this time.
this machine seems really not protected
btw.
trying connection is always on 2479, 8085, 3246.
DROP...
74.6.22.105 - attacking
my computer can't stop the attacking virus. I don't know how to remove that virus. help me to protect my computer.. plz... thanks...
75.125.39.74 - ISA 2006 FW intrusion detection
Description: ISA Server detected a possible Internet Protocol (IP) half-scan attack from IP address 75.125.39.74....
92.241.190.252 - Router Attack
Over the last month I have received over two hundred attacks from IP 221.192.199.46 on my router. I don't know what this attacks is but I would sure like some more information as to what its intent i...
75.125.39.74 - abnormal TCP flag attack
alert Firewall abnormal TCP flag attack detected, DROP [count=2] 75.125.39.74:6877 x.x.x.x:1234 ACCESS BLOCK...
75.125.39.74 - Intrusion.Generic.TCP.Flags.Bad.Combine.attack TCP
5/18/2010 3:16:56 PM Detected: Intrusion.Generic.TCP.Flags.Bad.Combine.attack TCP from 75.125.39.74 to local port 1234 Absent...
75.125.39.74 - Combine attack
17/05/2010 19:28:55 Detected: Intrusion.Generic.TCP.Flags.Bad.Combine.attack Absent TCP from 75.125.39.74 to local port 1234...
Kaspersky antivirus displays the following:
Detected: Intrusion.Win.DCOM.exploit TCP from 89.134.58.189 to local port 135...
221.195.73.86 - constant attempts to connect on 1080
Frequent hits (probably hourly) from 221.195.73.86 TCP port 12200 into TCP port 1080. Firewall is refusing them...
221.195.73.86 - constant attempts to connect on 1080
Frequent hits (probably hourly) from 221.195.73.86 TCP port 12200 into TCP port 1080. Firewall is refusing them...
125.45.109.166 - Since 27-04-2010 DDOS and Port Scan of two IPs
Netgear Router on two IP addresses in the 82.153/16 range report DOS and Port Scan from this IP address. Email reports to .CN NOC are now blocked.
Typical Report
TCP Packet - Source:125.45.109.166,1...
113.15.66.252 - Detected: Intrusion.Win.MSSQL.worm.Helkern
5/14/2010 12:50:01 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 113.15.66.252 to local port 1434
...
71.186.49.89 - Trying to extract information from my computer
My firewall sends me an alert every 3 minutes or so, telling me someone is trying to get info from my computer. Seems that there is no way to block them so would like to find out how to stop these att...
122.225.100.154 - 5/11/2010 4:51:46 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1434 Absent
5/11/2010 4:51:46 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1434 Absent...
218.65.229.146 - Detected: Intrusion.Win.MSSQL.worm.Helkern
5/11/2010 4:03:03 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.65.229.146 to local port 1434
...
89.244.196.201 - Intrusion Attempt from this address
Norton's blocked an intrustion attempt, occuring on Tues 11 May, 5.10pm AUS. Risk: NMap Xmas Scan
89.244.196.201, 2687
...
221.130.140.18 - Detected: Intrusion.Win.MSSQL.worm.Helkern
5/10/2010 4:40:03 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 221.130.140.18 to local port 1434 Absent
...
221.130.140.18 - 5/10/2010 9:17:03 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 221.130.140.18 to local port 1434 Absent
5/10/2010 9:17:03 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 221.130.140.18 to local port 1434 Absent...
95.211.101.132 - Several attacks daily.
I get a Attack Detection Report from my firewall daily, several time a day from the ip 95.211.101.132 alone. ...
221.195.73.86 - attempting VNC access 8 MAY 2010
221.195.73.86 attempting VNC access to personal computer in Los Angeles 8 May 2010...
82.36.163.128 - attempting SOCKS and SSH access 8 MAY 2010
222.208.183.218 attempted socks access and SSH access on 8 MAY against a personal computer in Los Angeles without permission or consent....
95.31.11.3 - I get repeated intrusion attempts from this IP
I'm using utorrent and Norton antivirus keeps giving me intrusion alerts. They all come from this IP address. It says he has an invalid TCP header....
218.204.73.195 - 5/8/2010 5:15:08 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.204.73.195 to local port 1434 Absent
5/8/2010 5:15:08 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.204.73.195 to local port 1434 Absent
and on the :
5/4/2010 1:17:18 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP...
60.161.78.155 - Network Intrusion
Intrusion.Win.MSSQL.worm.Helkern from 60.161.78.155 at 12:28 PST 5/6/2010
...
122.225.100.154 - udp from 122.225.100.154 intrusion. win.mmsql.worm.helkern
on the :
5/8/2010 8:13:57 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1434 Absent
and on the:
5/6/2010 4:14:42 PM Detected: Intrusion.Win.MSSQL.worm.H...
218.204.73.195 - Intrusion.Win.MSSQL.worm
2010/05/07 10:35:16 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.204.73.195 to local port 1434...
I have been getting nightly connection attempts from IP Address 125.45.109.166 on Port 12200. They continue to cycle through the following connection ports:
tcp/554 is rtsp - Real Time Streaming Pro...
221.12.160.198 - 221.12.160.198 everyday / 5 days already
Norton Security Suite, firewall on smart setting picked up a port scan from 221.12.160.198 port 12200 for the past 5 days, about twice to three times daily.
I really hope they don't get in into my co...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
5/6/2010 3:56:18 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 122.225.100.154 to local port 1434
...
221.192.199.49 - Kernel : Intrusion
Constant Alert of 'Kernel Intrusion' from src=221.192.199.49 to my router almost everyday; full up the syslog.
kernel: Intrusion -> IN=ppp_0_38_1 OUT= MAC= SRC=221.192.199.49 DST=xxx.xxx.xxx.xxx LE...
125.45.109.166 - Firewall Port Scan continually
[Firewall Log-PORT SCAN] TCP Packet - 125.45.109.166 --> ww.xx.yy.zz
Sniffing my firewall ports for 6 days now (continually)....
78.72.146.184 - Norton identifies hacking attempt from this IP address
Norton antivirus detects that an attempt to hack my PC was made from this IP address. 5 attempts in the last few minutes!
NMap Xmas Scan ...
78.72.146.184 - Norton identifies hacking attempt from this IP address
Norton antivirus detects that an attempt to hack my PC was made from this IP address. 5 attempts in the last few minutes!...
58.215.75.62 - Checking for Vulnerabilities
destination port is 10000 which use the TCP protocol.
Trying to access /etc/shells from port 10000. Likely scanning for webmin Vulnerabilities....
221.192.199.49 - May 2 16:51:22 kernel: Intrusion detected from 221.192.199.49. Source port is 12200, and destination port is 8000 which use the TCP protocol.
Tried to gain access over the past 2 days about 6 times per day ....
61.160.216.63 - Continuous attempt to penetrate my system.
These Chinese originated ip125.45.109.166:12200 (and other ports) is continuously popping up in the blocked firewall alert. Doesnât anyone taking action to stop these attacks from these hackers? Any...
221.192.199.46 - This user never gives up!
221.192.199.46 is being blocked, but doesn't stop trying to "break in"! My firewall log is filling up with line after line with this IP address.
Please get this user barred from the Internet forev...
67.18.213.122 - Tried to introduce Trojan
67.18.213.122 has tried attacking my computer once in the last day with a Trojan, using the address of google.anayltics.com.fhccvgjohscc.info as the attacking url/cpu...
91.212.226.59 - Constantly Attacking my Firewall
Hourly (at a minimum) my Internet Protection Software is blocking a known attack pattern from this IP address....
222.45.112.59 - constant port scanning by 222.45.112.59
Constant portscans done by this IP. really annoying!!! Blocked him permanently and all IP starting with 222.
Have done portscan on his IP and found several open ports... Let have a go8...
67.18.213.122 - Tried to introduce Trojan
[SID: 23663] HTTP Trojan Mebroot Request detected.
ns1.conneccionlatina.net is the last HOP in the back trace. ...
125.45.109.166 - intrusion attempts
Repeatedly attempts to access my computer. Hopefully all attempts have been succesfully blocked so far....
192.194.110.74 - NBSS
The following ip: 192.194.110.74 has been today constantly hitting and we got the following report from our firewall: nbss_decoder: NBSS.Invalid.Fragment...
192.228.153.222 - NBSS
The following ip: 192.228.153.222 has been today constantly hitting and we got the following report from our firewall: nbss_decoder: NBSS.Invalid.Fragment...
66.96.130.235 - Request.Smuggling
The following ip: 66.96.130.235 has been today constantly hitting and we got the following report from our firewall: http_decoder: HTTP.Request.Smuggling...
125.45.109.166 - Attempted port scanning
Firewall caught an attempt to scan ports. First time I've noticed this I.P. Looks like its been around, though. Can you block their originating server if you can identify it?...
125.45.109.166 - Um What?
My antiviris popped up and said this IP was sending me a virus but it was blocked, thank goodness. Why is there not more governing on the internet to block this or even prosicute the ones who are beh...
125.45.109.166 - China
Hm. It port scanned me 19 times- all fortunately blocked by my firewall. Thats so sketchy! I wonder whos trying to hack us from beijing...
60.161.78.155 - Detected: Intrusion.Win.MSSQL.worm.Helkern
2010/04/28 01:21:16 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 60.161.78.155 to local port 1434...
70.67.141.165 - an attack detected and stopped by Avast software
I received warning from my anti-virus software of DCOM Exploit. Traced WHOIS info to Shaw Communications in Nanaimo, British Columbia....
59.53.16.76 - 4/25/2010 4:11:10 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 59.53.16.76 to local port 1434 Absent
4/25/2010 4:11:10 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 59.53.16.76 to local port 1434...
60.161.78.155 - Detected: Intrusion.Win.MSSQL.worm.Helkern
4/25/2010 1:51:29 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 60.161.78.155 to local port 1434
...
117.87.35.251 - Port 45457 Probes From 117.87.35.251; 4 tcp
Apr 25 05:33:58 localhost kernel: ipfw: ##### Deny TCP 117.87.35.251:4260 12.76.209.130:45457 in via ppp0
Apr 25 05:34:01 localhost kernel: ipfw: ##### Deny TCP 117.87.35.251:4260 12.76.209.130:45457...
Apr 25 00:40:34 localhost kernel: ipfw: ##### Deny UDP 67.161.201.232:27092 12.76.209.130:45457 in via ppp0
Apr 25 00:43:01 localhost kernel: ipfw: ##### Deny UDP 99.235.12.82:30488 12.76.209.130:45...
123.11.240.130 - Eighteen connection attempts in one second
Apr 24 04:07:39 localhost kernel: ipfw: ##### Deny TCP 123.11.240.130:12200 12.76.216.126:3246 in via ppp0
Apr 24 04:07:40 localhost kernel: ipfw: ##### Deny TCP 123.11.240.130:12200 12.76.216.126:24...
41.230.239.87 - Port 65162 probes from this IP and others using UDP and TCP
Apr 23 23:17:23 localhost kernel: ipfw: ##### Deny UDP 189.38.181.201:57697 12.76.235.173:65162 in via ppp0
Apr 24 00:15:14 localhost kernel: ipfw: ##### Deny UDP 74.240.254.199:50952 12.76.235.173:6...
123.4.42.80 - 29 connection attempts
Apr 23 04:44:09 localhost kernel: ipfw: ##### Deny TCP 123.4.42.80:12200 4.154.28.3:2479 in via ppp0
Apr 23 04:44:09 localhost kernel: ipfw: ##### Deny TCP 123.4.42.80:12200 4.154.28.3:8000 in via pp...
89.202.157.215 - backdoor attack
a computer with ip from this address has attempted to aces my computer and perform buffer overflow attack
...
123.4.42.80 - 28 connection attempts
Apr 22 12:23:38 localhost kernel: ipfw: ##### Deny TCP 123.4.42.80:12200 4.154.27.89:7212 in via ppp0
Apr 22 12:23:38 localhost kernel: ipfw: ##### Deny TCP 123.4.42.80:12200 4.154.27.89:9415 in via ...
ip24-253-28-133. - linux firewall picks it up as a icmp
i have been doing computer security from 1995...
123.4.42.80 - 41 connection attempts in three seconds
Apr 21 22:10:00 localhost kernel: ipfw: ##### Deny TCP 123.4.42.80:12200 12.76.217.18:8085 in via ppp0
Apr 21 22:10:00 localhost kernel: ipfw: ##### Deny TCP 123.4.42.80:12200 12.76.217.18:3246 in vi...
123.4.42.80 - Fifteen connection attempts in one second
Apr 21 21:02:55 localhost kernel: ipfw: ##### Deny TCP 123.4.42.80:12200 12.76.242.157:1080 in via ppp0
Apr 21 21:02:55 localhost kernel: ipfw: ##### Deny TCP 123.4.42.80:12200 12.76.242.157:8000 in ...
124.232.152.116 - Looking for Http relay
124.232.152.116 - - [19/Apr/2010:13:59:10 +0100] \"GET http://www.wantsfly.com/prx2.php?hash=66E3C9ED4E2D2D92D4DB5E050050ECBCF86B108F253C HTTP/1.0\" 404 288 \"-\" \"Mozilla/4.0 (compatible; MSIE 6.0; ...
221.192.199.35 - 221.192.199.35
I found these in my error_log:
[Sun Apr 18 19:04:09 2010] [error] [client 221.192.199.35] script '/var/www/html/prx2.php' not found or unable to stat
[Mon Apr 19 17:57:41 2010] [error] [client 221.1...
202.109.191.2 - Detected: Intrusion.Win.MSSQL.worm.Helkern
4/21/2010 3:26:16 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 202.109.191.2 to local port 1434...
60.195.94.204 - ICMP scan - part of a new Botnet
Message meets Alert condition
2010-04-20 21:01:49 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=831144 duration=0 user=N/A group=N/A rule=0 policy...
218.148.42.254 - ICMP scan - part of a new Botnet
Message meets Alert condition
2010-04-21 01:51:20 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=837335 duration=0 user=N/A group=N/A rule=0 policy...
213.5.129.243 - ICMP scan - part of a new Botnet
Message meets Alert condition
2010-04-21 07:22:22 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=841919 duration=0 user=N/A group=N/A rule=0 policy...
59.61.160.67 - ICMP scan - part of a new Botnet
Message meets Alert condition
2010-04-21 07:22:22 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=841919 duration=0 user=N/A group=N/A rule=0 policy...
123.11.242.231 - port scanning
Heard a news report that these constant port scans are perpetrated by the North Korean government operating out of Beijing China for the purpose of gaining detailed information of every computer on th...
221.192.199.48 - Constant port scanning
Heard a news report that these constant port scans are perpetrated by the North Korean government operating out of Beijing China for the purpose of gaining detailed information of every computer on th...
222.45.112.59 - Constant port scanning
Heard a news report that these constant port scans are perpetrated by the North Korean government operating out of Beijing China for the purpose of gaining detailed information of every computer on th...
222.45.112.59 - Continual SYN Port Attacks
My firewall keeps intercepting SYN Port attacks from this IP address. This has been going on beginning NOV 2009 up to present. Perp does not seem to be getting through. Any ideas on what they might be...
218.64.237.219 - Intrusion.Win.MSSQL.worm.Helkern
2010/04/21 05:14:00 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.64.237.219 to local port 1434...
68.166.236.197 - attempted attack - part of a botnet
Message meets Alert condition
2010-04-20 05:19:27 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=803724 duration=0 user=N/A group=N/A rule=0 policy...
88.87.90.170 - attempted attack - part of a botnet
Message meets Alert condition
2010-04-20 06:47:00 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=804912 duration=0 user=N/A group=N/A rule=0 policy...
200.138.215.223 - attempted attack - part of a botnet
Message meets Alert condition
2010-04-20 08:38:09 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=806693 duration=0 user=N/A group=N/A rule=0 policy...
80.24.208.116 - attempted attack - part of a botnet
Message meets Alert condition
2010-04-20 10:11:33 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=809473 duration=0 user=N/A group=N/A rule=0 policy...
83.231.123.233 - attempted attack - part of a botnet
Message meets Alert condition
2010-04-20 12:41:25 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=814275 duration=0 user=N/A group=N/A rule=0 policy...
86.74.246.240 - attempted attack - part of a botnet
Message meets Alert condition
2010-04-20 14:11:49 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=820286 duration=0 user=N/A group=N/A rule=0 policy...
217.15.151.2 - attempted attack - part of a botnet
Message meets Alert condition
2010-04-20 14:40:43 device_id=FGT2002803033671 log_id=0022013001 type=traffic subtype=violation pri=warning vd=root SN=823097 duration=0 user=N/A group=N/A rule=0 policy...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
4/20/2010 4:24:20 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1434 Absent
...
200.57.151.171 - Buffer Overflow Attempt
Attempted to exploit the Microsoft Color Management Module by over flowing the buffer several times. User was looking up phone numbers on a spanish yellow-book site....
89.83.88.26 - Keylogger activity deteced on my pc!
First i get on my pc anti-virus crap turns on oh yeah can\\\\\\\'t forget about the PORN THAT KEEPS JUST APPEARING ON MY PC!Please make him stop hacking into my computer!!!! i wrote down the ip adress...
114.120.120.57 - Keylogger activity deteced on my pc!
First i get on my pc anti-virus crap turns on oh yeah can\\\'t forget about the PORN THAT KEEPS JUST APPEARING ON MY PC!Please make him stop hacking into my computer!!!! i wrote down the ip adresses o...
57.60.63.252 - Keylogger activity deteced on my pc!
First i get on my pc anti-virus crap turns on oh yeah can\'t forget about the PORN THAT KEEPS JUST APPEARING ON MY PC!Please make him stop hacking into my computer!!!! i wrote down the ip adresses of ...
147.148.108.63 - Keylogger activity deteced on my pc!
First i get on my pc anti-virus crap turns on oh yeah can't forget about the PORN THAT KEEPS JUST APPEARING ON MY PC!Please make him stop hacking into my computer!!!! i wrote down the ip adresses of t...
212.26.189.132 - DCOM Exploit
I use Avast Antivirus program and everyday some ip\'s try to hack into my computer. Avast reports \"DCOM Exploit\"s everyday. I caught this one lately,actually it\'s written 212.26.189.132:135/tcp. I ...
123.11.242.231 - intruder attempt blocked by firewall
in the last three days somebody has tried to hack my pc,the firewall picked up the ip 123.11.242.231 and its from China.These dam chinese have nothing better to do.,Well we all know that the chinese g...
68.87.74.166 - firewall caught intrusion attempt
firewall caught intrusion attempt
Sourse IP 68.87.74.166...
82.36.163.128 - attack from 66.246.252.40
Source port is 42871 and destination port is 22 which use the TCP protocol...
82.36.163.128 - attack from 222.208.183.218
Source port is 12200 and destination port is 8080 which use the TCP protocol...
60.161.78.155 - Network attack Intrusion.Win.MSSQL.worm.Helkern
2010/04/17 02:18:41 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 60.161.78.155 to local port 1434
...
122.225.100.154 - helkern
Network Intrusion.Win.MSSQL.worm.helkern
taken care of by kaspersky
attack came from 122.225.100.154 (cn)
...
Blocked communications from, Inbound TCP connection. Remote address.local service is (221.192.199.46, Port (2479) Date and Time:- 15th April 2010 14:49 (UTC) Dublin, Edinburgh, Lisbon, London...
213.163.89.106 - Watch out for 213.163.89.106
Watch out for this IP that appears to come from Holland but may originate elsewhere.
213.163.89.106 is bad news, try to block it...
60.161.78.155 - Network attack Intrusion.Win.MSSQL.worm.Helkern
Event Network attack detected happened on computer ********* in the domain ***** on Tuesday, April 13, 2010 9:13:47 AM (GMT-05:00)
Network attack Intrusion.Win.MSSQL.worm.Helkern: UDP from 60.161.78....
213.163.89.106 - trying acces to a illegal hacking homepage
trying acces to a illegal hacking homepage, same as the user said before....
im playing my games and get timed out or connection losses at same time my netgraph showing inbound traffic flooding of over 1000-2000 when normal ranges are around 300....
83.136.12.22 - 5 x in 15 minutes
my norton antivirus reported an attack by this ip adress - multiple times - thought i'd report it. wonder what it wants?...
61.175.243.101 - Detected: Intrusion.Win.MSSQL.worm.Helkern
4/8/2010 11:36:22 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.175.243.101 to local port 1434
...
86.125.5.171 - Bad IP keeps connecting to my IP every 4 minutes.
As per Subject:
The IP 86.125.5.17 first connected to my private FileServer yesterday afternoon (Easter Sunday) using a Get command for www.yahoo.com.
It obviously failed since I am not running a pr...
60.161.78.155 - network attack Intrusion.Win.MSSQL.worm.Helkern
My firewall tends to popup with this alerts. It happening from past dayz....
61.235.46.146 - Kaspersky reports Intrusion.Win.MSSQL.worm.Helkern
3/30/2010 10:32:34 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.235.46.146 to local port 0
Attack blocked by Kaspersky...
68.184.166.246 - Multiple attempts 1 every minute for last 24 hours
Found attack from 68.184.166.246.
Source port is 3927 and destination port is 6346 which use the TCP protocol.
Multiple attempts multiple source addresses all with same destination port 6346...
129.190.176.219 - 129.190.176.219 NEWPORT USA
THIS BASTARD IS TRYING TO GAIN ACCESS INTO MY COMPUTER FORCING PORT UDP 26649 SEVERAL TIMES PER DAY FFROM FEW DAYS , ATTACKS REJECTED BY MY FIREWALL...
222.86.62.237 - idiots chinese
3/26/2010 3:56:23 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 222.86.62.237 to local port 1434 Absent...
222.86.62.237 - mf
3/25/2010 12:30:08 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 222.86.62.237 to local port 1434...
221.192.199.48 - this thread is fake and gay.
this PC is obviously infected with malware and is part of a botnet. If you don\'t know what malware or botnet is, look it up on google....
64.15.142.167 - Unauthorized access to port 3389-RDP
Several consecutive attempts to login to server.
(
ip-64-15-142-167.static.privatedns.com
Thu, 2010-03-25 00:21:51 - TCP Packet - Source:64.15.142.167,33010 Destination:<myserveraddress>,3389 - [...
222.59.157.145 - Constant Network Attack Alert from IP Add: 222.59.157.145
IP Attack on my network. Blocked by Symantec Endpoint Protection....
62.63.160.100 - intrusion.generic.tcp.flags.bad.combine.attack
was attacked with "intrusion.generic.tcp.flags.bad.combine.attack" from 62.63.160.100 twice on 22/03/2010...
69.117.90.22 - an intrusion attempted by 69.117.90.22
An intrusion attempted by 69.117.90.22 on march 22 2010 11:34.
...
115.89.24.180 - I'm issuing SYN Floods on 115.89.24.180
HPING 115.89.24.180 (eth1 115.89.24.180): S set, 40 headers + 0 data bytes
len=46 ip=115.89.24.180 ttl=111 DF id=31286 sport=443 flags=SA seq=0 win=16616 rtt=295.5 ms
DUP! len=46 ip=115.89.24.180 tt...
209.62.45.43 - Sistematic attack 209.62.45.43
During the last hour, ip 209.62.45.43 fustigates my computer, with intervals of 5 seconds, often several times within one second.
I installed a firewall due to instability and frequent chrashes in my...
209.85.195.13 - Sistematic attack detected
My firewall has detected sistematic attack from ip 209.85.193.13...
190.176.142.211 - MS RPC Network DDE BO detected.
Traffic has been blocked from this application: C:\\Windows\\System32\\svchost.exe...
174.37.201.137 - 174.37.201.137 &67.228.177.148 Dallas USA
THOSE 2 IP\"S work toghether to hack my computer from port 4 to upper ports to hack it....ASSHOLES!!!!...
124.190.176.219 - 124.190.176.219 City:Melbourne
This IP 124.190.176.219 is trying to hack my computer using port 26649 , is keep sending me packets , blocked by my firewall.......
38.107.160.21 - IP 38.107.160.21 was probing my network
This IP was probing my Network, so I put a block on there IP in iptables, and I also issued a SYN flood attack on them. But also spoke with a guy at PSINet which was very nice and informed me to send ...
114.42.199.147 - Port scan from Taiwan
=>Found attack from 114.42.199.147.
Source port is 2445 and destination port is 445 which use the TCP protocol.
Sat Mar 20 22:53:32 2010...
121.11.86.68 - Port scan from China
=>Found attack from 121.11.86.68.
Source port is 6000 and destination port is 135 which use the TCP protocol.
Sat Mar 20 23:39:52 2010...
190.90.59.10 - Port scan from Bogota, Columbia
=>Found attack from 190.90.59.10.
Source port is 3969 and destination port is 445 which use the TCP protocol.
Sat Mar 20 23:40:53 2010
...
115.89.24.180 - IP Subnet Broadcast Amplification
Security alert type
IP Subnet Broadcast Amplification
IP source address 115.89.24.180
Number of attempts 61
Time at last attempt 3/21/10 12:48:06 AM...
207.46.199.180 - Microsoft attacking my port 80?
dialer0_ingress_acl denied tcp 207.46.204.243(11479)
Many packets sent from various ports from the address ranges below over an extended period of days. My machines are all os x.
207.46.204.*
...
207.46.199.180 - Microsoft attacking my port 80?
dialer0_ingress_acl denied tcp 207.46.204.243(11479)
Many packets sent from various ports from the address ranges below over an extended period of days. My machines are all os x.
207.46.204.*
...
207.46.199.180 - Microsoft attacking my port 80?
dialer0_ingress_acl denied tcp 207.46.204.243(11479)
Many packets sent from various ports from the address ranges below over an extended period of days. My machines are all os x.
207.46.204.*
...
189.115.227.102 - Norton Antivirus Alert
Norton antivirus popped up with a warning that a NMap Null Scan was blocked from the IP address 189.115.227.102...
69.63.176.173 - constant Network Attack Alert from IP Add: 69.63.176.173
I have been receiving a lot of network IP attack alert from this IP Add. My Symantec Endpoint Protection says that it is being blocked and that it has been logged, but whenever I check the logs, the ...
71.195.228.149 - Intrusion.Generic.TCP.Flags.Bad.Combine.attack!
Intrusion.Generic.TCP.Flags.Bad.Combine.attack!
Intrusion.Generic.TCP.Flags.Bad.Combine.attack!
Intrusion.Generic.TCP.Flags.Bad.Combine.attack!
Intrusion.Generic.TCP.Flags.Bad.Combine.attack!
Intr...
58.57.17.194 - 3/18/2010 2:22:07 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 58.57.17.194 to local port 1434
3/18/2010 2:22:07 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 58.57.17.194 to local port 1434...
222.186.24.37 - son of a b....
this person has been trying to hack my computer for 3 or 4 days now !!...
82.89.211.65 - 82.89.211.65 Rome
this IP is keep sending me packets on port 23486 all those packets ae blocked by firewall........
75.75.254.11 - Zen Cart attack
75.75.254.11 3/15/2010 9:25:16 PM - whois GeoLocate IP DNS Block IP /shop2/install.txt
75.75.254.11 3/15/2010 9:25:16 PM - whois GeoLocate IP DNS Block IP /zencart/install.txt
75.75.254.11 3/15/2010...
221.195.73.86 - Chinese archaic gutter scum
221.195.73.86 port 6000 incoming connection alert. yeah you goto hell...
221.7.160.230 - IP spoofing
- IP spoofing on netbios-ns_udp port and protocol
- try to connect on my FTP server too....
61.175.243.101 - network attack
network attack Intrusion.Win.MSSQL.worm.Helkern Network 61.175.243.101 61.175.243.101 ...
99.231.72.177 - Inbound TCP connection blocked
On 03/13/2010 Norton Internet Security Suite blocked ~40 attempts all coming within one hour from address 99.231.72.177 to gain access to my local port 48468. Precise wording by Norton:"Unused port bl...
222.86.62.237 - 222.86.62.237
Intrusion.Win.MSSQL.worm.Helkern UDP from 222.86.62.237 to local port 1434...
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180...
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180...
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180...
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180...
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180...
222.86.62.237 - Detected: Intrusion.Win.MSSQL.worm.Helkern
3/12/2010 10:24:30 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 222.86.62.237 to local port 1434 Absent
...
222.190.117.166 - Try to login
This IP address is try to login to my Home Network.
my home network using MikroTik and this IP is trying more than once....
218.22.244.45 - Detected: Intrusion.Win.MSSQL.worm.Helkern
3/11/2010 2:12:07 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 112.140.25.195 to local port 1434 Absent
...
206.169.171.58 - Morfeus soapCaller.bs Scan
It got page not found, on my drupal site. Monday, March 8, 2010 - 22:29...
221.192.199.46 - scans every 10-15 seconds
port 3246 & 8085
Blocked incoming TCP connection request from 221.192.199.46:12200...
115.89.24.180 - scans every 10-15 seconds
port 3246 & 8085
Blocked incoming TCP connection request from 115.89.24.180:12200...
221.192.199.48 - scans every 10-15 seconds
port 3246 & 8085
Blocked incoming TCP connection request from 221.192.199.48:12200...
193.33.88.7 - 444 attempts to access my system overnight
193.33.88.7 made 444 attempts to access my system overnight, these are the blocked attempts who knows how many sucessfull ones were made!...
222.86.62.237 - Blocked by Firewall
2010.03.07 18:50;
Intrusion.Win.MSSQL.worm.Helkern UDP from 222.86.62.237 to local port 1434...
218.30.22.82 - Intrusion on port 1434
07/03/2010 13:22:20 Intrusion.Win.MSSQL.worm.Helkern 218.30.22.82 UDP 1434
This IP trying to attack my system!...
92.233.113.233 - Attack on my computer
My antivirus stopped the attack coming from the following IP address 92.233.113.233 coming from UK Southend -on-sea....
61.175.243.101 - Detected: Intrusion.Win.MSSQL.worm.Helkern
3/7/2010 1:36:58 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.175.243.101 to local port 1434...
60.173.11.20 - Probing ports 1433 (MS SQL) and 2967 (used by Symantec)
Over a three day period, SonicWall TZ-100 detected and dropped several occurrences of probes of port 1433 (default port for MS SQL Server) and port 2967 (used by Symantec products). Inspection of ear...
68.87.74.166 - Intrusion Attempt
Norton Security Suite noted an intrusion attempt from this IP on port 53...
81.108.16.209 - Blocked intrusion attempts
Norton Internet Security blocked 6 NMap Xmas scans and 1 NMap Null scan. All traffic on TCP port 57029. IP autoblocked by Norton for 30 minutes. Attemps to ping address resulted in "General Failure...
222.086.062.237 - network attack intrusion.win.mssql.worm.helkern 222.86.62.237
network attack intrusion.win.mssql.worm.helkern 222.86.62.237...
58.57.17.194 - Detected: Intrusion.Win.MSSQL.worm.Helkern
3/2/2010 3:04:58 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 58.57.17.194 to local port 1434 Absent
...
219.149.53.239 - Intrusion
01/03/2010 14:26:28
Intrusion.Win.MSSQL.worm.Helkern
219.149.53.239 UDP 1434
My firewall detected this IP trying to hack in to my system!!!...
222.179.5.106 - Intrusion.Win.MSSQL.worm.Helkern
UDP from 222.179.5.106 to local port 1434 is problem that
...
88.107.109.4 - Intrusion detected
from 88.107.109.4. Source port is 65056, and destination port is 445 which use the TCP protocol.
...
My Norton Anti Virus Software Informed me of a stopped attack from this IP Address....
217.23.5.204 - An intrusion attempt by 217.23.5.204 was blocked
HTTP Fake Anti-virus Install Request 4...
93.186.118.142 - see description
My router did advise me that somebody under IP 93.186.118.142, 3605 tried to get with no permit into my computer on 24th of February. Firefox said this bloody user gives no information on his website ...
202.173.191.92 - see d.m.
My router did advise me that somebody under IP 202.173.191.92, 4982 tried to get with no permit into my computer on 14th of February. Firefox said this bloody user takes for trust certification a cert...
218.30.22.82 - Detected: Intrusion.Win.MSSQL.worm.Helkern
2/26/2010 5:01:32 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.30.22.82 to local port 1434
...
124.173.184.18 - Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 124.173.184.18 to local port 1434
2/21/2010 Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 124.173.184.18 to local port 1434...
61.160.234.5 - Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.160.234.5 to local port 1434
2/21/2010 Detected:Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.160.234.5 to local port 1434...
10.10.10.2 - Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 10.10.10.2 to local port 1434
two attempts on 2/22/2010...
218.30.22.82 - Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.30.22.82 to local port 1434
for the past three days continuously trying to attempt atleast 3 times....
210.51.52.151 - Possible DoS HGOD SynKiller Flooding
2010-02-24 21:50:07 Possible DoS HGOD SynKiller Flooding 210.51.52.151
Attacked my ip address....
61.160.234.5 - Detected: Intrusion.Win.MSSQL.worm.Helkern
2/22/2010 11:35:05 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.160.234.5 to local port 1434 ...
122.225.100.154 - MSQL worm to port 1434
Kaspersky 2010 reports Win.MSQL.worm.Helkern to port 1434. Again....
195.5.161.4 - Trying to download Trojan
I dont understand your technical terms, but this is what my anti nasty software spotted.
13/02/2010 14:39:30
Infected Trojan program Trojan.Win32.FraudPack.alhp
http://195.5.161.4/download/Setup...
Device type: WAP
Running: 2Wire embedded
OS details: 2Wire 1701HG wireless ADSL modem, 2Wire 2700HG, 2700HG-B, 2701HG-B, or RG2701HG wireless ADSL modem, 2Wire 2701HG wireless ADSL modem, 2Wire Shas...
202.99.11.99 - Detected: Intrusion.Win.MSSQL.worm.Helkern
2/20/2010 4:24:55 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 61.237.159.25 to local port 1434 Absent
This one is constantly poping up from various ip's ! cant any action be taken aga...
209.17.74.144 - Microsoft Paint Buffer Overflow Exploit
2010-02-19 08:51:10 EXPLOIT Microsoft Color Management Module Buffer Overflow 209.17.74.144...
216.86.148.11 - Microsoft Paint Buffer Overflow Exploit
2010-02-19 08:39:16 EXPLOIT Microsoft Color Management Module Buffer Overflow 216.86.148.11...
218.75.61.30 - Network attack Intrusion.win.mssql.worm.Helkern
Kaspersky internet security reported network attack Intrusion.win.mssql.worm.Helkern from 218.75.61.30 on 17-02-2010 10:03 hrs...
116.9.95.1 - Daily attack from 116.9.95.1
Found attact from 116.9.95.1 from 63582 or 6XXXX something port to destination 10000 using tcp....
192.168.2.1 - Hacker report from Norton
Attacking computer: 192.168.2.1, 80
Hello, this IP number attempts to hack into my pc almost every night (Aus, Sydney time. 9pm).
With several attempts on each session.
Norton detects this ...
60.191.131.138 - VIRUS SQL Slammer Activity from 60.191.131.138
Network attack -VIRUS SQL Slammer Activity from 60.191.131.138...
86.99.180.160 - Intrusion.Generic.TCP.Flags.Bad.Combine.attack
Intrusion.Generic.TCP.Flags.Bad.Combine.attack...
195.5.161.4 - Fake Malware Alert
While browsing, a pop up window states the computer is underattack by malware and to click to install malware blocking software. Upon closing the window, a fake virus scanning screen comes up showwing...
61.160.234.5 - Detected: Intrusion.Win.MSSQL.worm.Helkern
2/11/2010 2:24:02 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.160.234.5 to local port 1434
...
192.168.1.1 (Por - Default block SSDP 192.168.1.1 (Port 2869) inbound tcp
I have looked in my firewall alerts and i have been receiving a lot of inbound TCP\'s from 192.168.1.1 (Port 2869). usually like 5-8 in just one second and sometimes 10 in a second about every 5 minut...
89.28.86.212 - Continual attempts to access system
This IP address is being continually reported by my firewall as attemting to logon to my system using various user names and passwords. So far has been blocked by firewall but seems to have made upto ...
204.147.181.142 - Firewall Alert
Firewall log: [DoS Attack: RST Scan] from source: 204.147.181.142, port 80, Sunday, February 07,2010 21:27:24
I have hundreds of scans from tFirewall log: [DoS Attack: RST Scan] from source: 204.14...
61.147.107.56 - Recent Firewall alert
Port blocked communications with inbound TCP connection with this person. Target was port 2967. Another attempt was logged from 60.173.11.137 to the same port an hour later. ...
127.139.94.214 - localhost 127.0.0.1 attempting to attack my computer
norton anti virus picked up a portscan someone trying to enter my pc and attack from attacking computer localhost 127.0.0.1, 49972 destination address 127.139.94.214, 23786. traffic description TCP, 4...
221.192.199.48 - Scans every 2 to 5 minutes
source port 12200, destination port 8000, 8085, and 8090. Repeated attempted unauthorized inbound sessions blocked by router. Also repeated TCP port scans detected. No valid reason whatsoever for t...
41.205.158.135 - Intrusion.Win.MSSQL.worm.Helkern
Below is the details of network attack that is reported on my pc by kaspersky.
02-02-2010 12:14:19 Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 41.205.158.135 to local port 1434...
218.85.134.102 - Net Spy attack dropped - 218.85.134.102, 6000
He's trying to break into law enforcement computer network .The net spy attack apprears daily . ...
94.31.241.184 - Detected: Intrusion.Win.MSSQL.worm.Helkern
2/1/2010 11:02:07 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 94.31.241.184 to local port 1434
...
218.30.22.82 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/30/2010 10:37:14 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.30.22.82 to local port 1434 Absent
...
67.29.139.234 - Bit Defender Blocks 67.29.139.234
Accoarding to this website its in Sherman Oaks dont know what it wants to do but its not getting past me......
58.240.227.19 - Net spy attack, port scans all in one day
Keep receiving alerts from this IP address, will try to submit a complaint to their abuse....
58.240.227.19 - Sub Seven Attack
Tried to get by with a sub-seven attack that got dropped by my FW, these attacks are beginning to be really annoying!...
218.75.95.244 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/26/2010 1:23:59 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.75.95.244 to local port 1434 Absent...
139.222.247.11 - port scanning
139.222.247.11, 59723 was scanning my ports for a hole in my firewall, I don\\\'t really appreciate that, I eventually just unplugged because he was persisting....
111.171.127.139 - Kaspersky says this is trying to get into my machine
111.171.127.139 has been identified as trying to access my computer...
212.252.124.15 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/24/2010 12:05:30 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 212.252.124.15 to local port 1434
...
62.213.100.140 - recent hits coming in on malwarebytes
I am being hit by a suspicious IP. These are hitting a lot....
89.248.172.172 - recent hits coming in on malwarebytes
I am being hit by a suspicious IP. This one is hitting a lot....
218.30.22.82 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/23/2010 10:51:50 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.30.22.82 to local port 1434 Absent ...
222.179.5.106 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/23/2010 10:08:25 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 222.179.5.106 to local port 1434 Absent
...
213.174.154.66 - I am recieving multiple hits 21.65.
All day long I receive multiple hits from this IP and others. 121.65.112.161 and 88.214.193.121 and 62.213.100.140. Here is my Malwarebytes log.
05:53:59 User MESSAGE Protection started successfull...
125.65.112.168 - I am recieving multiple hits 21.65.
All day long I receive multiple hits from this IP and others. 121.65.112.161 and 88.214.193.121 and 62.213.100.140. Here is my Malwarebytes log.
05:53:59 User MESSAGE Protection started successfull...
212.252.124.15 - 22/01/2010 20:58:00 UDP from 212.252.124.15 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern
22/01/2010 20:58:00 UDP from 212.252.124.15 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/22/2010 11:54:18 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 122.225.100.154 to local port 1434...
85.178.160.57 - maybe a virus
A strage file wants to connect to this IP, its maybe a Virus or Trojan....
121.28.90.36 - Kernal Intrusion
Jan 21 06:04:44 (none) user.alert kernel: Intrusion -> IN=ppp_0_38_1 OUT= MAC= SRC=121.28.90.36 DST=90.208.130.111 LEN=40 TOS=0x00 PREC=0x00 TTL=104 ID=256 PROTO=TCP SPT=6000 DPT=1521 WINDOW=16384 RES...
96.6.120.11 - This ip address 96.6.120.11 tried to hack our firewall
20-Jan-10 10:00:45 TCP 96.6.120.11 [Policy rule] 80 70.52.198.137 (Safe@Office) 21384
20-Jan-10 10:00:45 TCP 96.6.120.11 [Policy rule] 80 70.52.198.137 (Safe@Office) 21373
20-Jan-10 10:00:45 TCP 96....
122.225.100.154 - Gefunden: Intrusion.Win.MSSQL.worm.Helkern on local port 1434
kaspersky alerts daily on this network attack...
60.190.49.243 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/20/2010 5:42:42 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 60.190.49.243 to local port 1434
...
61.139.105.163 - 61.139.105.163 keeps hacking me
can someone think of a way to report this nut job...
61.139.105.163 - 61.139.105.163 keeps hacking me
can someone think of a way to report this nut job...
61.158.162.9 - This has to stop
I receive daily reports of attacks/scans being directed at my server from this IP address.
Complained through their ABUSE but to no avail....
77.206.127.172 - TCP Xmas Tree scan
Attempted to scan my ports through a TCP XMas Tree attack - annoying but the firewall dropped it...
212.252.124.15 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/18/2010 1:28:10 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 212.252.124.15 to local port 1434...
218.23.37.51 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/16/2010 2:02:09 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.23.37.51 to local port 1434 Absent
...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
i am getting alot of ip address attacking my computer from china
Kaspersky alerting me daily ...
218.22.244.45 - 13/01/2010 2:38:38 PM Detected Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.22.244.45 to local port 1434
Yet again another Helkern attack from China. Looks like I might have to block ALL incomming traffic from China....
74.125.87.105 - 74.125.87.105 WORM helkern attack on port 1344
74.125.87.105 WORM helkern attack on port 1344....6 times in 6 seconds....you crap bastard!!!...
89.149.236.46 - This IP was part of a virus alert on ISO Hunt Website
This IP has been attacking my firewall non stop!...
212.252.124.15 - UDP from 212.252.124.15 on local port 1434
1/11/2010 22:50:56 UDP Ð¾Ñ 212.252.124.15 на локалÑнÑй поÑÑ 1434 ÐÑÑÑÑÑÑвÑÐµÑ ÐбнаÑÑжено: вÑоÑжение. Ðин. MSSQL.worm. Helkern...
My anti-malware is constantly reporting malicious acitvity from IP 213.174.157.10...
218.204.137.156 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Detected: Intrusion.Win.MSSQL.worm.Helkern
aspersky firewall alerted that ------------------------------------------ Network attack intrusion.Win.MSSQL.worm.Helkern:UDP from 218.204.137.156 to local ...
218.204.137.156 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Detected: Intrusion.Win.MSSQL.worm.Helkern
aspersky firewall alerted that ------------------------------------------ Network attack intrusion.Win.MSSQL.worm.Helkern:UDP from 218.204.137.156 to local ...
218.204.137.156 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Detected: Intrusion.Win.MSSQL.worm.Helkern
aspersky firewall alerted that ------------------------------------------ Network attack intrusion.Win.MSSQL.worm.Helkern:UDP from 218.204.137.156 to local ...
80.229.205.62 - Attempts to log on to netwrok
Numerous attempts to log into our network, being blocked by firewall & server security. Thisseems to have been happening for the last 3 days....
218.23.37.51 - UDP from 218.23.37.51
Kaspaskey internet secruity alert for blocked Network Attack from 218.23.37.51...
218.75.95.244 - Detected: Intrusion.Win.MSSQL.worm.Helkern
1/4/2010 4:11:45 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.75.95.244 to local port 1434...
1/3/2010 3:44:36 PM UDP from 222.47.22.18 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern
If it\'s not one IP, it\'s another - constantly (once an hour or so). Very persistent ...
208.43.95.175 - Trojan
My fire has popped up in the last 15 minutes, saying that someone from this ip address is attempting to do something to my computer through a trojan...
208.43.95.175 - Trojan
My fire has popped up in the last 15 minutes, saying that someone from this ip address is attempting to do something to my computer through a trojan...
208.43.95.175 - Trojan
My fire has popped up in the last 15 minutes, saying that someone from this ip address is attempting to do something to my computer through a trojan...
222.208.183.218 - high security alert by firewall
recently one of my accounts have been changed, my firewall has logged all possible intruders. but this one is the only high alert, 222.208.183.218
others are:
188.192.160.217
221.195.73.68
80.97.1...
61.139.105.163 - Trying to gain access
Firewall message saying system wanted to accept an incoming connection from IP Adress 61.139.105.163 - See this has been a long term problem I take it nothing can be done?!...
81.214.98.119 - Attempted hack on my firewall.
User on Turhish IP address has been trying to hack into my firewall....
61.139.105.163. - hacking to get info
61.139.105.163
problems
tcp port scanning
cn... china?
get em.
disconnects
complete system wipe
virus...
218.75.95.244 - Attempted hack MS SQL Stack BO
BLOODY CHINESE AGAIN!!! ITEMS OUT OF CHINA PURCHASED WITH EBAY (MP3 Player)HAD A VIRUS. SELLER CLAIMS IT MUST HAVE COME FROM FACTORY. ANTI-VIRUS CAUGHT HOWEVER ATTACKS FROM CHINA STARTED AND NOW HAPP...
202.99.11.99 - 12/30/2009 3:55:03 PM UDP from 218.204.137.156 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern
This specific attacker (IP) has been at it for at least a year, off and on. I cannot believe there has been no kind of international block or something on this guy....
61.139.105.163 - Trying to scan ports - Blocked by Firewall
Just started using a new security software and it has blocked this IP address, 61.139.105.163, from scanning my ports from the first day I installed it. This IP has tried to scan my ports several time...
219.149.53.239 - 92.249.246.46
Kaspersky report : 2009.12.30. 13:22:06 Intrusion.Win.MSSQL.worm.Helkern 219.149.53.239 UDP 1434...
122.225.100.154 - 92.249.246.46
Kaspersky report : 2009.12.30. 13:22:06 Intrusion.Win.MSSQL.worm.Helkern 219.149.53.239 UDP 1434...
210.245.126.130 - There once was a young hacker from Dung ....
There once was a young hacker from Dung
And after my router had sung
I noticed his tries and then heard his cries
When he couldn't get past the first rung!...
67.18.244.106 - Sends HTTP requests with invalid URI
Seems to call soapCaller.bs with with preamble that resembles linux stack data. (\0x04\b == 0x0804.... which is default address of program data when loaded on linux)
error.log:[Mon Dec 21 19:28:43...
201.19.108.60 - Outpost Firewall Pro, Attack Detection, Attack Short Fragments
Outpost firewall is showing a short fragments attack. Was blocked so nothing else come of it...
158.49.245.201 - Large login attempts to root account
hello,
I am getting large number of fail login attempt in my server firewall from this IP address.
Thanks,...
61.139.105.163 - Intrusion Detection
hello . in all day my firewall have alert
Intrusion Detection for from IP 61.139.105.106
for more result about this ip see below link :http://www.ip-adress.com/whois/61.139.105.163...
218.75.95.244 - attacking UDP Port 1434
28/12/2009 5:22:37 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.75.95.244 to local port 1434 ...
201.208.17.12 - attacking UDP Port 1434
28/12/2009 4:38:42 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 201.208.17.12 to local port 1434...
61.139.77.234 - attacking UDP Port 1434
28/12/2009 4:30:53 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.139.77.234 to local port 1434...
61.139.77.234 - attacking UDP Port 1434
28/12/2009 4:38:42 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 201.208.17.12 to local port 1434...
122.225.100.154 - 122.225.100.154 - Network attack Intrusion.Win.MSSQL.worm.Helkern
12/13/2009 at 2:27:14 PM - Attacks reported by Kasperski....
222.45.112.59 - Continual scanning my computer
222.45.112.59 is continually trying gain access to my computer. we need a wizard to hack his computer and break his permanently....
218.204.137.156 - Detected: Intrusion.Win.MSSQL.worm.Helkern
12/23/2009 12:00:41 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.204.137.156 to local port 1434 Absent
...
212.252.124.15 - Detected: Intrusion.Win.MSSQL.worm.Helkern
12/23/2009 10:54:50 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 212.252.124.15 to local port 1434 Absent...
212.156.5.254 - Tracked numerous attempts to login via ssh to root ID
Logged over 105 attempts to login to server using SSH. Majority of attempts were on Dec 12 and Dec 14 2009....
218.22.244.45 - Detected: Intrusion.Win.MSSQL.worm.Helkern
12/21/2009 11:20:33 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.22.244.45 to local port 1434
...
take over my browser. Hijacks my browser and does a fake virus scan, wants me to download an .exe file.
This program or adware or hacker or virus/worm and hijacker pops up and takes over my browser. ...
take over my browser. Hijacks my browser and does a fake virus scan, wants me to download an .exe file.
This program or adware or hacker or virus/worm and hijacker pops up and takes over my browser. ...
61.160.216.63 - www.wantsfly.com
Some communist china jackass is all over my log. I am going to block the entire continent of china. Its bad enough our idiot CEOs give our jobs away and our asshole president Obama bowing to them, t...
218.23.37.51 - Attack
17 dec 2009: 8:15 pm:
Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.204.137.156 to local port 1434...
221.195.82.103 - Attacks from source port 6000
Router firewall shows attacks from this IP, source port 6000 with various destination ports on my network....
190.2.29.193 - Detected: Intrusion.Win.MSSQL.worm.Helkern
12/15/2009 3:22:30 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 190.2.29.193 to local port 1434
...
122.225.100.154 - Detected: Intrusion.Win.MSSQL.worm.Helkern
12/15/2009 10:41:43 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 122.225.100.154 to local port 1434 Absent
...
221.130.140.18 - Detected: Intrusion.Win.MSSQL.worm.Helkern
12/14/2009 1:19:18 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 221.130.140.18 to local port 1434
...
222.219.218.129 - Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 222.219.218.129
12/14/2009 12:32:49 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 222.219.218.129 to local port 1434 Absent...
61.139.105.163 - My computer scanned by 61.139.105.163
this guy from China has been scanning my ports every day for the past few months.How can I stop this?...
10.1.1.14>>>HOP # 19..........
OrgName: Internet Assigned Numbers Authority
OrgID: IANA
Address: 4676 Admiralty Way, Suite 330
City: Marina del Rey
StateProv: CA
PostalCode:...
218.30.22.82 - repeat attempted attacks
13/12/2009 13:19:58 Network Attack Blocker Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.30.22.82 to local port 1434
...
218.30.22.82 - Detected: Intrusion.Win.MSSQL.worm.Helkern
14/12/2009 12:06:33 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.30.22.82 to local port 1434...
12/13/2009 1:26:20 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 190.2.29.193 to local port 1434 Absent...
12.48.150.3 - continuous showings in my firewall
For days this ip address ( 12.48.150.3 )
has been shown continuously in my firewall logs.
Always to port 12984.
I can't see any reason for this.
Even on a reboot and fresh connection to the int...
61.139.105.163 - Trojan spreader posibily
Tries to connect on Port 808 then second attempt on 1025. Winhole, Wingate Trojan likely. This IP is now banned via my firewall....
61.139.105.163 - this guy is an asshole
I KEEP GETTING scanned by this guy daily! persistant little #%T$%$R#!...
66.154.32.207 - Illegel spyware/malice scams
This IP is linked to www.porno.com, c/o Cozier & Associates. Hosted by www.directnic.com. Many people have been scammed and computers have been damaged with spyware download in conjunction with a bogu...
209.249.47.217 - This ip keeps attacking on port 33704.
This ip address and others in the range 209.249.47.*
It keeps pinging on port 33704. Its not getting through so this might be a DoS attack. I am not too sure. Any suggestions about how to make i...
212.252.124.15 - Kaspersky report a atack
07/12/2009 13:23:31 Detectados: Intrusion.Win.MSSQL.worm.Helkern Ausente UDP de 212.252.124.15 para porta local 1434
...
218.204.137.156 - Network Attack intrusion
Kaspersky firewall alerted that ------------------------------------------
Network attack intrusion.Win.MSSQL.worm.Helkern:UDP from 218.204.137.156 to local port 1434.Blocked.Attacking computer has n...
218.85.134.102 - Net Spy Attack by 218.85.134.102
This guy started hitting my home AND office networks yesterday with constant \"Net Spy Attacks\" (as reported by my firewall). About a 100 attempts so far and I\'ve now blocked that address....
95.28.5.13 - Network attack
From this ip 95.28.5.13 i received a network attack,but my firewall stoped him.I guess:)...
212.252.124.15 - SQL Slammer worm
My Comodo firewall had blocked DOS attack from him and i think he is using other IP addresses as well
212.252.124.15
218.204.137.156
60.190.49.243
219.149.53.239
218.30.22.82
190.2.29.193
218...
219.149.53.239 - SQL Slammer worm
My Comodo firewall had blocked DOS attack from him and i think he is using other IP addresses as well because all of the blocks is prventing this guy from aiming for my file called C:\\\\Program Files...
222.37.37.33 - SQL Slammer worm
My Comodo firewall had blocked DOS attack from him and i think he is using other IP addresses as well because all of the blocks is prventing this guy from aiming for my file called C:\\Program Files\\...
218.204.137.156 - SQL Slammer worm
My Comodo firewall had blocked DOS attack from him and i think he is using other IP addresses as well because all of the blocks is prventing this guy from aiming for my file called C:\Program Files\Mi...
81.152.33.126 - 62 times system intrusion in around 3 hours
Firewall warned me 62 times between 6pm and now. Still continuing...
81.152.33.126 - 62 times system intrusion in around 3 hours
Firewall warned me 62 times between 6pm and now. Still continuing...
151.95.170.113 - 48 times system intrusion in around 3 hours
Firewall warned me 48 times between 6pm and 9:30pm...
218.23.37.51 - Still trying to get into port 1434
Blocked incoming UDP packet from 218.23.37.51:2194 to 207.68.242.154:1434...
61.147.107.56 - Obsessed with port 2967
Blocked incoming TCP connection request from 61.147.107.56:12200 to 207.68.242.154:2967...
115.170.75.176 - Blocked incoming UDP packet
Blocked incoming UDP packet from 115.170.75.176:1184 to 207.68.242.154:1434...
218.22.244.45 - UDP packet attempt
If I could get my hands on his mouse, do you know where I would put it?...
212.252.124.15 - Detected: SQL Worm propagation attempt
Numerous attempts to attack udp port 1434....
218.22.244.45 - Detected: Intrusion.Win.MSSQL.worm.Helkern
10/31/2009 10:29:47 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.22.244.45 to local port 1434...
218.22.244.45 - Detected: Intrusion.Win.MSSQL.worm.Helkern
10/31/2009 10:29:47 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.22.244.45 to local port 1434
...
151.32.240.221 - Attempt of intrusion
My firewall reported 45 attempts of intrusion in 5 hours on 29 november between 19pm and midnight...
222.186.25.9 - firewall allert " System 222.186.25.9" blocking
firewall allert " System 222.186.25.9" blocking.
please Block it.
I think it is a try to hack me.
...
218.6.15.146 - Prolonged, port probe. 218.6.15.146
Hop Sing\'s Home Address by traceroute: latitude: 39.9289, IP longitude: 116.3883. src_ip=218.6.15.146- and scan process over a number of days. (26 times) Port Scan attack Primary Send port 6000 inden...
218.249.117.196 - Network attack
I using windows xp sp 2 and having Kaspersky internet security 2010 version. Usually when I start my internet connection, after 10 to 15 mins I will get a message saying "NETWORK ATTACK INSTUSION.WIN....
222.219.231.132 - Attack from 222.219.231.132
11/26/2009 2:56:04 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 222.219.231.132 to local port 1434...
122.227.164.96 - Continuos router attack
=>Found attack from 122.227.164.96.
Source port is 12200 and destination port is 8090 which use the TCP protocol.
Thu Nov 26 15:53:53 2009
...
60.173.10.154 - Tried to communicate with my computer
My Spy sweeper program blocked an attempted communication from my computer to IP address: 60.173.10.154. I am not sure how the program got on my computer that is trying to contact the rogue web site. ...
69.63.187.16 - stupid Facebook (apps?) ?
I'm access Facebook, use some apps (zynga, 6Waves and other producers), and I'm in a NAT.
My Firewall was receiving this!
Stupid programming?
Status: A non-SYN packet was dropped because it was se...
202.103.9.51 - trying to attack my pc
network attack intrusion.win.mssql.worm.helkern not blocked. Ip may be spoofed....
202.103.9.51 - trying to attack my pc
network attack intrusion.win.mssql.worm.helkern not blocked. Ip may be spoofed....
66.0.10.82 - TCP Flood
Firewall log:
Sat 2009-11-14 09:18:32 TCP flood From 66.0.10.82 port:62591 To 82.**.***.*** port:808 droped
Sat 2009-11-14 09:18:32 TCP flood From 66.0.10.82 port:62608 To 82.**.***.*** port:4...
64.12.7.167 - Hacking, Hijacking and many other illegal acts
He is dodsing me and hacking my computers and sql injected attempts....
221.195.73.68 - several port scans
received several ports scan today from 222.208.183.218... looks like he wan't to poke his/her nose on....
211.100.229.252 - Kaspersky report "IntrusionWin.MSSQL.worm.Helkern"
Date: 2009-11-11
The intrusion was blocked by Kaspersky....
74.63.225.44 - high security alert@169.228.66-251
Update:: on; 169.228.66-251........
| 92.242.144.7 | 169.228.66-251 | ?(United Kingdom) | * | 111 | --x---- | Barefruit Ltd. ...
74.63.225.44 - high security firewall alert@port 1080
high security firewall alert@port 1080.
the firewall stoped the destination to port 1080,
Packet sent from; 74.63.255.44,(port tcp-12200)and reverse 44.255.63.74.istn.net
11-10-2009...time; 19:3...
63.243.14.117 - Firewall: *TCP_IN Blocked*
Time: Tue Nov 10 06:10:35 2009 +0000
IP: 63.243.14.117 (US/United States/vetjobs.com)
Hits: 11
Blocked: Temporary Block
Sample of block hits:
Nov 10 06:09:01 apollo kernel: Firewall: *TCP_IN Bl...
211.100.229.252 - 2009-11-09 18:23:38 Intrusion.Win.MSSQL.worm.Helkern 211.100.229.252
2009-11-09 18:23:38 Intrusion.Win.MSSQL.worm.Helkern 211.100.229.252...
friedberg -Germany...
76.115.198.17 - network attack
thip ip has attacked 3 times my pc. and my firewall has blocked it. please do something 4 it. i dont know who is this hacker....
60.160.245.117 - Intrusion.Win.MSSQL.worm.Helkern 60.160.245.117
08/11/2009 22:22:10
Intrusion.Win.MSSQL.worm.Helkern
60.160.245.117 UDP 1434...
60.160.245.117 - Intrusion.Win.MSSQL.worm.Helkern 212.252.124.15
08/11/2009 22:22:10
Intrusion.Win.MSSQL.worm.Helkern
212.252.124.15 UDP 1434...
98.134.224.106 - repeated attacks today...first ever.
I have been on attack all day...11-08-09. Have NEVER had this problem. Says they have been blocked, but it just cont and sometimes the ISP will change. I dont know. Have done scan and nothing found......
169.254.129.35 - Connection Attempt
Firewall protection
Connection attempt has been Blocked
on 11/8/2009, 8:34:07 PM
Source IP address: 169.254.129.35
This IP address has been attempting to connect into my computer since 10/20/09.
...
60.172.210.21 - Unknown inbound connection from this ip
This IP tried to connect to svchost. Purpose unknown as connection was refused....
2009-11-05 18:16:32 Intrusion.Win.MSSQL.worm.Helkern 202.103.9.51...
61.148.100.130 - he`s trying to get in my computer
300 characters? you cotta be joking with me!!! read the above..............................................................................................................................................
61.160.216.63 - 61.160.216.63 Trying to scan my computer...
My firewall caught him... scanning my ports...whoever this is, they need to catch him, STOP him and ban him from computers!!!!!...
68.94.157.1 - I have received an intrusion attemp alert by 68.94.157.1
I keep getting an Alert! pop-up stating that an intrusion attemp was made by 68.94.157.1 my computer says...\"Network traffic 68.94.157.1 matches the signature of a known attack. The alert was just to...
68.94.157.1 - I have received an intrusion attemp alert by 68.94.157.1
I keep getting an Alert! pop-up stating that an intrusion attemp was made by 68.94.157.1 my computer says..."Network traffic 68.94.157.1 matches the signature of a known attack. The alert was just to ...
60.173.10.154 - Tried to communicate with my computer
My Spy sweeper program blocked an attempted communication from my computer to IP address: 60.173.10.154. I am not sure how the program got on my computer that is trying to contact the rogue web site. ...
64.214.85.253 - >10,000 alerts every day on port 33435udp, 33436udp
Since mid of September 2009, the system is hammering or firewalls with some 10,000 packets every day. Not only our systems are affected, that offending (or misconfigured) device is known to other secu...
200.35.74.206 - Attempting to access my network
[INFO] Sun Nov 01 17:05:12 2009 Blocked incoming TCP connection request from 200.35.74.206:4881 ...
221.195.73.68 - Attempting to access my network
Sun Nov 01 16:19:12 2009 Blocked incoming TCP connection request from 221.195.73.68:6000
Several attempts were made....
24.58.167.209 - Port Scanning
19 port scans over the course of 1 hour and 16 minutes. Continued to scan until I terminated my internet connection. Source DNS is cpe-24-58-167-209.twcny.res.rr.com according to ZoneAlarm....
77.245.144.228 - Zyxel firewall report portscan
Recieved multiple zyxel firewall alerts like this one (different ports):
No. Time Source IP Destination IP Note
1|10/31/2009 23:39:25 |77.245.144.228:2538 ...
76.218.103.56 - port scan
Oct 30 23:42:50 kernel: PORT SCANNER ATTACK detected from 76.218.103.56. Source port is 3303, and destination port is 24464 which use the TCP protocol.
...
212.252.124.15 - : Intrusion.Win.MSSQL.worm.Helkern
31/10/2009 12.39.08 Rilevato: Intrusion.Win.MSSQL.worm.Helkern Assente UDP da 212.252.124.15 sulla porta locale 1434...
64.4.35.253 - I have been recieving alerts regarding this IP address
He's being an a-s :). Very annoying
reports of blocks from my firewall
program, that are coming from this
address 64.4.35.253 . Some one needs
to terminate this person, as a
provider to the inte...
97.92.71.179 - Port Scanning
Scanned 34 ports in 15 minutes. Continuing to scan until I terminated my internet connection. Source DNS is 97-92-71-179.dhcp.stcd.mn.charter.com according to ZoneAlarm....
74.63.192.66 - Port Scanning
34 port scans in the last 28 minutes. It is continuing so scan while I type this. Source DNS is 66-192-63-74.reverse.lstn.net according to ZoneAlarm. Simultaneously receiving port scans from two ot...
218.204.137.156 - Intrusion.Win.MSSQL.worm.Helkern UDP 1434
received log in kaspersky stating this attacker from UDP port 1434...
received log in kaspersky stating this attacker from UDP port 1434...
122.225.100.154 - received log in kaspersky stating this attacker from UDP port 1434
received log in kaspersky stating this attacker from UDP port 1434...
217.66.204.26 - Iranian IP address repeatedly hitting our firewall
IPtables is repeatedly alerting blocked attempts from this Iran based address - suspect server hack attempted....
217.132.53.83 - Intrusion.Generic.TCP.Flags.Bad.Combine.attack
27/10/2009 16:20:27 Intrusion.Generic.TCP.Flags.Bad.Combine.attack 217.132.53.83 TCP 4772
form my firewall
pda1000@gmail.com
thx
israel. r...
76.163.220.194 - 122.227.164.96[port 12200] Tried to connect to my PC. I manually blocked it after looking here.
122.227.164.96[port 12200] Tried to connect to my PC. I manually blocked it after looking here...
122.225.100.154 - Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern is constantly sent from that ip.
I\\\\\\\'m another victim i suppose?...
61.129.60.23 - This IP is trying to get into my system.
Source IP
61.129.60.23
Destination IP
74.235.75.89
Protocol
TCP
Source Port
27236
Destination Port
22
TCP Flags
02 ( syn )...
189.74.152.210 - 189.74.152.210 > try to conecting by Radmin (Commodo Firewall)
189.74.152.210 > try to conecting by Radmin (Commodo Firewall)...
network attack intrusion generic tcp flags bad combine attack ip 121.54.92.134...
202.103.9.51 - network attack Intrusion.Win.MSSQL.worm.Helkern
I also have Kaspersky software, and it alerts me to the fact that 202.103.9.51 is attacking my ports....
218.23.37.51 - 218.23.37.51
24.10.2009 16:21:17
Intrusion.Win.MSSQL.worm.Helkern
UDP: 218.23.37.51 at local Port 1434
24.10.2009 18:59:05
Intrusion.Win.MSSQL.worm.Helkern
UDP: 218.23.37.51 at local Port 1434
...
202.103.9.51 - 222.179.251.11,02.103.9.51,122.225.100.154,218.30.22.82
23.10.2009 13:36:08 Intrusion.Win.MSSQL.worm.Helkern! IP-Adresse des Angreifers: 218.23.37.51. Protokoll/Dienst: UDP auf lokalem Port 1434. Zeit: 23.10.2009 13:36:08
23.10.2009 07:11:20 Intrusion.Win...
123.134.95.199 - Constant Port Scanning
ditto as the above....out of all the IPs on my firewall logs, this is the worst offender. Port scanning on 8080, 8000, 7212, 8800, 8118, 9090, 8085....
124.237.121.52 - Firewall detected attack from 124.237.121.52
Hardware firewall reporting several attacts each day from this IP and blocking them all...
77.245.144.147 - Firewall detected attack from 77.245.144.147
Hardware firewall reporting several attacts each day from this IP and blocking them all...
79.114.20.248 - Firewall detected attack from 79.114.20.248
Hardware firewall reporting several attacts each day from this IP and blocking them all...
77.68.0.128 - Firewall detected attack from 77.68.0.128
Hardware firewall reporting several attacts each day from this IP and blocking them all...
77.245.144.228 - Firewall detected attack from 77.245.144.228
Hardware firewall reporting several attacts each day from this IP and blocking them all...
121.14.229.199 - Firewall detected attack from 121.14.229.199
Hardware firewall reporting several attacts each day from this IP and blocking them all...
112.110.56.204 - repeated port scans on different ports definitely a hacker
Hacker on the loose....keeps changing ports scanned. Keeps trying....
202.103.9.51 - network attack Intrusion.Win.MSSQL.worm.Helkern
Kapersky is alerting me everyday many times per day of network attack , blocked Intrusion.Win.MSSQL.worm.Helkern from diiferent IP\\\'s including 222.219.218.99, 202.103.9.51, 218.204.137.156, 2122.22...
174.129.28.21 - 174.129.28.21 seattle highports inbound TCP 50500
174.129.28.21 seattle highports inbound TCP 50500...
66.18.77.194 - nmap null scan
repeated scans. Rather annoying. Don't know why it's scanning my computer....
78.52.61.228 - 78.52.61.228 tryed to hack my system high ports inbound
78.52.61.228 tryed to hack my system high ports inbound TCP 18687...
122.227.164.96 - Panda Power
It would seem this bastard has hijacked my address, changed my password, and is using my unit as a proxy. We sure need to bust his links or counter-attack in enough force to at least shut him down fo...
79.204.146.88 - 79.204.146.88...Oldenburg GERMANY
several inbound attacks at port 4445..GMT+1....northwest Germany...
222.219.236.189 - Intrusion.Win.MSSQL.worm.Helkern 222.219.236.189 UDP 1434
An Attempt to attack the computer...
61.166.104.67 - Network attack Intrusion.Win.MSSQL.worm.Helkern
Constant attacks reported by Kasperski...
218.30.22.82 - Network attack Intrusion.Win.MSSQL.worm.Helkern
Constant attacks reported by Kasperski...
218.30.22.82 - Network attack Intrusion.Win.MSSQL.worm.Helkern
Constant attacks reported by Kasperski...
122.225.100.154 - Network attack Intrusion.Win.MSSQL.worm.Helkern
Constant attacks reported by Kasperski...
2009-10-09 04:37 - Network attack Intrusion.Win.MSSQL.worm.Helkern . Blocked. Failed to block attacking computer, probably its address is falsified.
Constant attacks reported by Kasperski...
61.145.255.255 - Network attack Intrusion.Win.MSSQL.worm.Helkern . Blocked. Failed to block attacking computer, probably its address is falsified.
Constant attacks reported by Kasperski...
169.254.103.179 - It makes my connection to shutdown constantly
Whenever I try to block communication to this IP, my connection gets lost and it\'s needed to restart the PC....
61.78.70.53 - 61.78.70.53 port scan
10/10/2009 12:30 PST
port scan attempt on 22 \"This connection attempt was probably a port scan attempting to find and exploit a vulnerability associated with the SSH Secure Shell application\"
Ge...
125.25.19.213 - Intrusion Detected
Intrusion.generic.tcp.flags.bad.combine.attack (via utorrent open port)...
87.97.108.138 - 87.97.108.138 JASKISER HUNGARY
this asshole is trying to break my firewall with TCP connection port 18678...
218.75.199.50 - Intrusion.Win.MsSql.worm.helkern
UDP attack on port 1434 by 218.30.22.82 .
Once again chinese. They have nothing else to do ? ...
83.223.162.42 - tried attacking my computer blocked by anti virus
anti virus reports it has known trojan characteristics...
83.223.162.42 - tried attacking my computer blocked by anti virus
anti virus reports it has known trojan characteristics...
121.14.229.199 - Repeated, ongoing attempts to infect my computer
My AVG Anti virus software is blocking repeated attempts by 121.14.229.199 every couple of days, when it attempts to infect my computer....
CAN HE NOT BE SHUT DOWN?...
218.200.115.195 - Here is again....
10/1/2009 12:48:59 PM UDP from 218.200.115.195 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern
...
189.74.152.210 - 189.74.152.210 malware&hacking IP , Brazil, Matupa city
189.74.152.210 malware&hacking IP , Brazil, Matupa city, this is a professional hacker, very dangerous one send trojans like Trojan Dadobra bru...and nasty stuff...
117.103.230.44 - Hanoi Vietnam ip 117.103.230.44
this IP from Vietnam was trying to intrude my firewall thru UDP 110 local port...
122.227.164.96 - 62.215.6.52 Misbehaving.
Attempting to hack for over 3 months now. How do I get them to stop?...
Intrusion : Win.MSSQL.worm.Helkern. Attackers IP : 61.145.123.141 Port 1434
1434...
123.134.95.199 - 123.134.95.199
Six times a day they do port scans, I too have blocked China 112.0.0.0-123.255.255.255...
190.210.25.161 - intrusion worm HELKERN - buenos aires Argentina
intrusion worm helkern from this IP 190.210.25.161 from ARGENTINA UDP 1434, who is this bastard???...
194.109.21.230 - Network Attack
This ip address (194.109.21.230) has been triggering my firewall/antivirus numerous times via IRC...
194.109.21.230 - Network Attack
This ip address (194.109.21.230) has been triggering my firewall/antivirus numerous times via IRC...
194.109.21.230 - Network Attack
This ip address (194.109.21.230) has been triggering my firewall/antivirus numerous times via IRC...
213.40.124.194 - Intrusion.WIN.DCOM.exploit
Kaspersky internet security 8.0.0.506 reported (time)24/09/2009 - (object) TCP from 213.40.124.194 to local port 135 - (Aplication) Absent - (Result) Detected:Intrusion.WIN.DCOM.exploit - (reason) no ...
123.134.95.199 - Port Scanning
Scaning ports tcp/ip 8085, 8080, 8000, and 3128. The built in fire wall in a mortorola dsl modem is stopping/blocking it. There was a malware in the form of a trojan on this computer that was removed ...
123.134.95.199 - Port Scanning
Scaning ports tcp/ip 8085, 8080, 8000, and 3128. The built in fire wall in a mortorola dsl modem is stopping/blocking it. There was a malware in the form of a trojan on this computer that was removed ...
221.192.199.41 - Port scans from 77.245.144.89
receiving TCP port scans from 77.245.144.89 Izmir, Turkey...
77.245.144.89 - Port scans from 77.245.144.89
receiving port scans from 77.245.144.89 Izmir, Turkey...
this person is all the time trying to use my internet /wireless and nortons keeps telling me its blocking port scans!!!...
222.122.156.55 - 222.122.156.55 port 6000 tiggered firewall alert
222.122.156.55 port 6000 triggered firewall alert
I'm not doing anything online outside USA, shows to be Soul Korea trying to access my system just now...
213.174.157.10 - 213.174.157.10 is reported by malwarebytes anti-malware
My anti-malware is constantly reporting about malicious acitviyt from IP 213.174.157.10...
85.17.211.163 - popups and virus
IP address 85.17.211.163 Keeps sending me virus\' and popups that keep on penetrating my firewall....
61.240.240.50 - 17-09-2009 12:45:36 UDP desde 61.240.240.50 al puerto local 1434 Detectados: Intrusion.Win.MSSQL.worm.Helkern
17-09-2009 12:45:36 UDP desde 61.240.240.50 al puerto local 1434 Ausente Detectados: Intrusion.Win.MSSQL.worm.Helkern...
61.145.123.141 - Firewall report (KIS2009) - Network atack blocker 5/day
My time is UTC+3. Reports from KIS2009 for last 3 days:
14.09.09 20:28:24 UDP from 61.145.123.141 to local port 1434 - Detected: Intrusion.Win.MSSQL.worm.Helkern
14.09.09 15:30:40 UDP from 61.145....
190.2.29.193 - Intrusion.Win.MSSQL.worm.Helkern! IP-Adresse des Angreifers: 218.23.37.51 Protokoll/Dienst: UDP auf lokalem Port 1434
Kasperky sagt,
16.09.2009 21:17:50 Intrusion.Win.MSSQL.worm.Helkern! IP-Adresse des Angreifers: 190.2.29.193. Protokoll/Dienst: UDP auf lokalem Port 1434. Zeit: 16.09.2009 21:17:50...
218.23.37.51 - 2X Intrusion.Win.MSSQL.worm.Helkern! IP-Adresse des Angreifers: 218.23.37.51 Protokoll/Dienst: UDP auf lokalem Port 1434
Kasperky sagt,
16.09.2009 19:34:11 Intrusion.Win.MSSQL.worm.Helkern! IP-Adresse des Angreifers: 218.23.37.51. Protokoll/Dienst: UDP auf lokalem Port 1434. Zeit: 16.09.2009 19:34:11
16.09.2009 21:...
219.129.164.150 - remote system trying to access my computer
8:11 PM on 9/13 TCP inbound protocol firewall gave a high risk alert that this IP was trying to access my computer. Blocked IP from access....
192.116.242.80 - Alert from this IP
Norton 360 firewall blocked this Ip because tell that was incurred in \"nmap null scan\"
be careful...
192.116.242.24 - Alert from this IP
Norton 360 firewall blocked this Ip because tell that was incurred in "nmap null scan"
be careful...
122.227.164.96 - Intrusion port scan attempt repeatedly
I also have had these SOB\'s bust through my firewall in the past several weeks and had outlook express destroyed, completely lost all my email. I am most certain it\'s these same SOB\'s that continue...
123.134.95.199 - Continual alarts from firewall - scanning ports
Have had numerous reports from firewall over last 4 days of intrusion attems from this IP being blocked by friewall...
123.134.95.199 - Continual alarts from firewall - scanning ports
Have had numerous reports from firewall over last 4 days of intrusion attems from this IP being blocked by friewall...
123.134.95.199 - Continual alarts from firewall - scanning ports
Have had numerous reports from firewall over last 4 days of intrusion attems from this IP being blocked by friewall...
66.129.65.24 - attacks rejected by firewall
Time: Wed Sep 9 22:27:31 2009 +0000
IP: 66.129.65.24 (US/United States/-)
Hits: 11
Blocked: Temporary Block
Sample of block hits:
Sep 9 22:26:09 knight kernel: Firewall: *UDP_IN Bl...
203.78.64.138 - Port 445 and ICMP destination unreachable traffic
very persistent probes from this source. Anyone seeing that too?...
76.187.201.247 - 07-09-2009 17:19:17 Detected: Intrusion.Generic.TCP.Flags.Bad.Combine.attack Absent TCP from 76.187.201.247 to local port 15596
"07-09-2009 17:19:17 Detected: Intrusion.Generic.TCP.Flags.Bad.Combine.attack Absent TCP from 76.187.201.247 to local port 15596"
Popped up on my Internet Security program, Kasper Internet Security...
61.160.216.63 - TCP connection dropped
TCP connection dropped 61.160.216.63, 12200, WAN WAN TCP Port: 7212 ...
59.56.108.77 - port scan
TCP ports:
8080, 80, 8000, and 7212 have been scanned from 59.56.108.77.....
123.134.95.199 - Scanning my computer
Original message from firewall
Somebody is scanning your computer.
Your computer\'s TCP ports:
8085, 9090, 8080, and 8800 have been scanned from 123.134.95.199.....
123.134.95.199 - Port scans
6-8 times a day, he started few days ago.
Somebody is scanning your computer.
Your computer's TCP ports:
8080, 8000, 8800, and 8118 have been scanned from 123.134.95.199..
anybody willing...
218.98.106.53 - Detected:Intrusion.Win.MSSQL.worm.Helkern
I use Google translate:
Kaspersky Internet Security I have just been informed of this IP is to attack my computer. KIS also announced that more servers can not block attacks, this can be IP author....
Repeated attacks on firewall Aug 31st to Sept 1st, 2009. All hours of day and night....
Repeated attacks on firewall Aug 31st to Sept 1st, 2009. All hours of day and night....
218.98.106.53 - Detected:Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern 218.98.106.53 UDP 1031...
218.98.106.53 - Helkern worm intrusions from this site
Continuously getting the following from my securit software (Kaspersky)
network attack Intrusion.Win.MSSQL.worm.Helkern 202.101.180.165...
80.184.57.63 - Intrusion Attemp
i have recieved several warnings by my firewall that IP 80.184.57.63 had attemped to attack my computer... i have recieved around 10-15 times by my firewall... In advanced detail what my firewall tell...
221.195.73.68 - Incoming TCP requests from China
My router logs show continuous Incoming TCP Connection Requests from this IP. My router is dropping them and I have my firewall configured to block the whole IP range of China....
125.65.112.161 - Incoming TCP requests from China
My router logs show continuous Incoming TCP Connection Requests from this IP. My router is dropping them.m
...
4.79.142.206 - Confirmed.
The user above is correct. This IP is used by GRC.COM for a firewall port scan......
4.79.142.206 - more Firewall Alerts
Possible port scan dropped - Source:4.79.142.206, 59556, WAN
Probable port scan dropped - Source:4.79.142.206, 59556, WAN
Probable TCP NULL scan dropped - Source:4.79.142.206, 59556, WAN
N...
61.147.107.56 - Found attack from 61.147.107.56.
Tue Aug 25 20:39:22 2009
=>Found attack from 61.147.107.56.
Source port is 6000 and destination port is 2967 which use the TCP protocol.
...
69.73.207.159 - Norton AV said they were trying to access my computer
TCP port 61986, they attempted to access my computer through this port. Norton Firewall alerted me to their attempted penetration. I am making it a point to report them. They attempted to penetrate...
78.154.216.44 - Norton AV said they were trying to access my computer
TCP port 61986, they attempted to access my computer through this port. Norton Firewall alerted me to their attempted penetration. I am making it a point to report them. They attempted to penetrate...
84.255.155.158 - Norton AV said they were trying to access my computer
TCP port 61986, they attempted to access my computer through this port. Norton Firewall alerted me to their attempted penetration. I am making it a point to report them. They attempted to penetrate...
85.17.211.163 - Complaint against IP 85.17.211.163
IP address 85.17.211.163 Keeps sending me virus\\\' and popups that keep on penetrating my firewall....
85.17.211.163 - Complaint against IP 85.17.211.163
IP address 85.17.211.163 Keeps sending me virus' and popups that keep on penetrating my firewall. ...
122.227.164.96 - RDP port open
122.227.164.96 - their RDP port is open! Someone should hack their admin account and shut them down!...
78.165.94.47 - We must stop this nonsence worldwide...
I got a Firewall allert of Trojan attack today. Now my messege to those hackers > \"In 21st century its really disappointing that,people are wasting there time for all this fraud attacks, when humans ...
82.77.211.3 - 82.77.211.3 Onesti -ROMANIA
scanning ports tryed to enter into my pc , attack repulsed by my firewall, sugi pula de zici ca e acadea fraere ce esti...
58.243.161.51 - 58.243.161.51 worm helkern attack
58.243.161.51 worm helkern attack from HEFEI China on UDP 1434 port stopped by firewall but tthe Ip is spoofed...
61.145.123.141 - 8/12/2009 2:52:09 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.145.123.141 to local port 1434
8/12/2009 2:52:09 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.145.123.141 to local port 1434
So is this site getting in on my computer or what? i got this a few times?
is my...
218.204.137.156 - 8/10/2009 SQL_SSRP_Slammer_Worm, 218.204.137.156, 8/10/2009 SQL_SSRP_StackBo, 218.204.137.156,
8/10/2009 SQL_SSRP_Slammer_Worm, 218.204.137.156,
8/10/2009 SQL_SSRP_StackBo, 218.204.137.156,...
79.17.197.128 - 79.17.197.128 AREZZO HACKER
trying hard this spaghetti seller to enter into my computer from telecom italia network....VA FANCULOOOOOOOO...
220.194.54.149 - I got alert in my KIS...
I gt an alert in KIS 8 that 220.194.54.149 ip address is attacking on my pc. That Bastard is from China. KIS Blocked him.
Details:
8/9/2009 6:09:32 PM
Detected: Intrusion.Win.MSSQL.worm.Helkern...
221.192.199.41 - Port scans
I have changed IPs but still it's trying to scan my ports:
security:958.088 Blocked Prot=6, 221.192.199.41:12200 > xx.xx.xx.xxx:8085, S Seq=5497010, Ack=0 -Disallowed Destination IP...
218.23.37.51 - Intrusion.Win.MSSQL.worm.Helkern
8/9/2009 1:35:15 PM Intrusion.Win.MSSQL.worm.Helkern 58.243.161.51 UDP 1434
...
192.168.1.24 - Always trying to access my computer
I have already received 2 alerts from my firewall that this IP address has been trying to access my files....
218.23.37.51 - If u knew u dubm asshole i would not had to write here..
8/5/2009 12:18:48 AM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 218.23.37.51 to local port 1434 Absent
...
222.161.2.46 - MSTASK.EXE 122.227.164.96 12200 Inbound TCP 1025 LocalHost
OUTPOST FireWall on - Win2000 - SP1
Block activity for application MSTASK.EXE
MSTASK.EXE 122.227.164.96
remote port 12200
Inbound TCP
local port 1025 (LocalHost)...
122.227.164.96 - 5 intrusion attempts from this IP address
Security software blocked repeated intrusion attempts from this IP address!...
195.130.130.133 - DENAIL OF SERVICE ATTACK
DENAIL OF SERVICE ATTACK
MS DOS ATTACKER !
HE TRIED MORE THEN 7 TIMES TO ATTACK MY PC.
However my PANDA GLOBAL PROTECTION 2010 Blocked The ATTACK !...
66.129.65.24 - 66.129.65.24 Charlotte NORTH CAROLINA hacker
this guy was trying several times to break my firewall , attacks rejected by firewall....
85.142.1.66 - application modification
attack from this site.
attempted modification of winlogon.exe, ssh.exe, ping.exe
related to attack from 218.93.205.24....
218.93.205.24 - attempted application change
218.93.205.24 (00-21-7c-77-c8-11)
tried to change
"winlogon.exe"
bad things, man....
209.85.229.99 - Firewall lit up
Blocked outgoing TCP packet from 192.168.0.130:1030 to 209.85.229.99:80 as RST:ACK received but there is no active connection
IP ....130 is my computer behind the NAT of router
This seems to be ...
118.93.191.163.4 - NMAP NULL SCAN on computer
This IP address to to run an NMAP NULL SCAN on my computer about twenty time within 5 minutes!!!!!!...
58.243.161.51 - network virus
kaspersky internet security detected this attack 7/27/2009 8:12:24 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 58.243.161.51 to local port 1434
...
218.206.139.152 - Network Virus
July 26, 2009 UDP from 218.206.139.152 to local port 1434: Detected- sqlslammer.a...
222.161.2.46 - 122.227.164.96 attempted portscan at least 5 times daily
Firewall is stopping these attempted portscans from this IP....
81.193.199.222 - Sacavam Portugal hacker
This IP 81.193.199.222 from PORTUGAL, is trying for 2 days to enterv into my pc searching different ports to enter into my computer using UDP ports , i think is a lousy hacker .... no succes but it is...
211.95.79.6 - prick keeps attacking my computer with a virus
prick keeps attacking my computer with a virus...
81.196.2.103 - 81.196.2.103 Bucharest asshole
this IP 81.196.2.103 was trying to enter into my computer today at 15:03pm from Bucharest , asshole , i am gonna report your ip the rds company to cut your connection from internet
...
147.156.124.211 - Hacker!
In the last hour or so 147.156.124.211 has been blocked by my firewall numerous times, trying to gain entrance to my computer and thus my files.
Damn Hacker Puta!...
221.192.199.41 - Many port scan from this IP: 221.192.199.41
From firewall log there are every day port scan from Chinese IP 221.192.199.41...
74.63.225.44 - Constant port probes
Remote ip address 74.63.225.44 port 12200
Probing local ports 6588, 9788, 9000, TCP(flags:S) at least once every hour....
222.208.183.218 - Constant port scanning and probe attempts
Remote ip address 222.208.183.218 port 12200
Probing local ports 8080, 1080, 8000, 7212 TCP(flags:S) at least once every hour....
218.185.195.83 - network attack
intrusion.win.mssql.worm.helkern my kaspersky firewall detected ip : 218.185.195.83 trying to load this : intrusion.win.mssql.worm.helkern into my system...
218.185.195.83 - network attack
intrusion.win.mssql.worm.helkern my kaspersky firewall detected ip : 218.185.195.83 trying to load this : intrusion.win.mssql.worm.helkern into my system...
202.99.11.99 - intrusion into my computer
intrusion.win.mssql.worm.helkern
my kaspersky firewall detected ip : 218.185.195.83 trying to load this : intrusion.win.mssql.worm.helkern into my system through a network server...
202.99.11.99 - intrusion into my computer
intrusion.win.mssql.worm.helkern
my kaspersky firewall detected ip : 218.185.195.83 trying to load this : intrusion.win.mssql.worm.helkern into my system through a network server...
202.99.11.99 - intrusion into my computer
intrusion.win.mssql.worm.helkern
my kaspersky firewall detected ip : 202.99.11.99 trying to load this : intrusion.win.mssql.worm.helkern into my system through a network server...
77.69.183.57 - Norton blocked an intrusion attempt
in 10 seconds Norton blocked 9 intrustion attempts to my computer from ip 77.69.183.57 with the risk name NMap Null Scan. Fortunately it didn't get to do any damage because my Norton program stopped i...
68.142.233.166 - port scanning from Sunnyvale California
68.142.233.166 and 76.13.15.56 two IP addresses from california trying hard to break my firewall.....they should rot in jail, assholes...
124.161.72.45 - Intrusion attempt blocked - NMap Xmas Scan
124.161.70.79 attempting many times over the past few days to get into my computer. Believed to be from CNC Group SiChuan province network located in the city of Deyang, China. Wonder what they are up...
92.48.78.245 - yet another scan
Somebody is scanning your computer.
Your computer's TCP ports:
5905, 5908, 5903, and 5904 have been scanned from 92.48.78.245.....
92.48.78.245 - 2 port scans today.
Somebody is scanning your computer.
Your computer\'s TCP ports:
5904, 5910, 5907, and 5909 have been scanned from 92.48.78.245..
Somebody is scanning your computer.
Your computer\'s TCP por...
124.161.72.56 - nmap xmas scan
On 6/30/2009, at 11:36 and 11:44 GMT -5, Norton blocked this ip address doing an "NMap Xmas Scan" on my machine, on a port that was forwarded to my machine from my router....
165.165.39.209 - Intrusion Attempts Reported by Norton
165.165.39.209 is trying to access my pc possibly trying to steal data. Luckily Norton has been blocking his attempts but it is getting annoying and now I want him removed if possible....
165.165.39.209 - Intrusion Attempts Reported by Norton
165.165.39.209 is trying to access my pc possibly trying to steal data. Luckily Norton has been blocking his attempts but it is getting annoying and now I want him removed if possible....
114.163.10.248 - Intrusion.Win.MSSQL.worm.Helkern Absent
6/28/2009 1:41:47 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.145.123.141 to local port 1434...
218.23.37.51 - Intrusion.Win.MSSQL.worm.Helkern Absent
6/28/2009 1:41:47 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.145.123.141 to local port 1434...
89.34.153.157 - Intrusion.Win.MSSQL.worm.Helkern Absent
6/28/2009 1:41:47 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.145.123.141 to local port 1434...
61.145.123.141 - Intrusion.Win.MSSQL.worm.Helkern Absent
6/28/2009 1:41:47 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.145.123.141 to local port 1434
...
60.161.78.144 - Intrusion.Win.MSSQL.worm.Helkern Absent
6/28/2009 3:14:16 PM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 60.161.78.144 to local port 1434
my kaspersky internet security detected this attack.and i have encountered this att...
118.88.13.34 - attack on port 3389
trying to connect on port 3389, which i use for remote desktop connection (not now i changed it), and appeared in my routers log file....
190.54.35.179 - attack on port 3389
this ip address was trying to connect on port 3389, which i use for remote desktop connection (not now after this i changed it), this appeared in my routers log file....
61.139.105.163 - port scans
TCP Packet - Source:61.139.105.163 Destination:79.197.xxx.xxx - [PORT SCAN]! ...
219.153.66.61 - Port scans
After blocking 2 diffrent IPs from china, including one with over 100 diffrent complains, I'm beeing scanned by this guy:
Your computer's TCP ports:
1080, 3128, 444, and 8000 have been scanned ...
87.1.6.19 - udp fire wall all time
61.184.255.175 this ip detail
61.184.255.175
Host Net Range Route Org. Name Country
61.184.255.175
61.183.0.0 - 61.184.255.255 CHINANET-HB
CN
Types of Offensive Actions by 61.184.255....
202.99.11.99 - Intrusion.Win.MSSQL.worm.Helkern
6/14/2009 8:32:41 PM UDP from 218.22.244.45 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern
...
41.246.211.118 - Detected: Intrusion.Win.DCOM.exploit Absent TCP from 41.246.211.118 to local port 135
network intrusion...
61.139.105.163 - scanning my ports
scanning ports, alerted firewall, attack was blocked according to firewall notification...
61.184.255.175 - 6/12/2009 2:36:01 AM Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 61.184.255.175 to local port
tried to hack me what more can i say...
118.168.169.93 - Port Scan
Just after blocking 61.139.105.163 (and having another scan from there) I was scanned by 118.168.169.93
Your computer's TCP ports:
1080, 8000, 8088, and 8080 have been scanned from 118.168.16...
61.139.105.163 - Port Scans
Repeted dailly scans.
Somebody is scanning your computer.
Your computer\'s TCP ports:
8888, 808, 3124, and 11825 have been scanned from 61.139.105.163.....
88.208.210.81 - Port Scan Detected - Firewall Alert
We got port scan detected attack from this IP : 88.208.210.81,TCP Scanned port list : 2675,2676,2677,2680,2681. ...
61.139.105.163 - 61.139.105.163(12200) scanning me daily from China
Some \\\"Slant Eye\\\" from China is eye-balling my ports (scanning) all the time... I am going to send him a \\\"Torpedo\\\". Something they can look at melting down their computer. I think it is g...
61.139.105.163 - Port Scam
This IP ADDRESS (61.139.105.163) is trying to hack on my computer and has been blocked by my firewall. Just want to report this IP trying to hack on to my PC....
88.148.238.204 - Tying to hack on to my pc
Here is the IP Address of the hacker. IP 88.148.238.204.
And their informations.
netnum: 88.148.236.0 - 88.148.239.255
netname: LANNENPUHELIN-NET
descr: Dynamic Adsl-pool
country: FI
admin-c: L...
218.23.37.51 - Intrusion.Win.MSSQL.worm.Helkern
Kaspersky AV report:
6/3/2009 3:43:49 PM PDT Intrusion.Win.MSSQL.worm.Helkern! Attacker's IP address: 218.23.37.51. Protocol/service: UDP on local port 1434. Time: 6/3/2009 3:43:49 PM
Intrusion ...
61.139.105.163 - Tying to hack on to my pc
This IP ADDRESS (61.139.105.163) is trying to hack on my computer and has been blocked by my firewall. Just want to report this IP trying to hack on to my PC....
88.109.23.70 - Tying to hack on to my pc
This IP ADDRESS is trying to TELNET on my computer and has been blocked by my firewall. Just want to report this IP trying to hack on to my PC....
91.184.69.46 - This is trying to telnet my computer.
This IP address ( 91.184.69.46 ) has been trying to telnet my PC and been blocked by my firewall. I just want to report this IP address. ...
61.160.216.63 - tring to get in
this chinise idiot is trying once again to get into my network on port 80...
124.229.197.207 - hitting 8010
for several hours now, 124.229.197.207 is hitting 8010, every couple of seconds....
61.139.105.163 - port scanning
Somebody is scanning your computer.
Your computer\'s TCP ports:
1080, 8000, 8088, and 8080 have been scanned from 118.168.171.241.....
118.168.171.241 - port scanning
Somebody is scanning your computer.
Your computer's TCP ports:
1080, 8000, 8088, and 8080 have been scanned from 118.168.171.241.....
61.137.90.253 - BROKE THRU MY ROUTER AND ACCESSED SERVICES. ACTING IN CONCERT WITH 61.139.105.163!!!
HAS BEEN ACCESSING SERVICES ON MY NETWORK STARTING 22ND MAY. ACTING IN CONCERT WITH 61.139.105.163. CAN SOMEONE STOP THESE GUYS PLEASE. TIRED OF THE DAILY PORT SCANS AND BREACHES INTO OUR SYSTEMS!!!!!...
82.17.152.54 - TCP attack on my network
Just one of the many many 1000\'s of IP addresses which are attacking my network via TCP on local port 135
Kaspersky reports it as
Intrusion.Win.DCOM.exploit...
62.150.107.119 - NMAP NUll Scann
This IP is constantly trying to attack my computer - repeatedly. It happens all day in most cases....
87.208.194.133 - Found attack from 87.208.194.133.
=>Found attack from 87.208.194.133.
Use the ICMP protocol.
...
218.12.53.10 - Found attack from 218.12.53.10
=>Found attack from 218.12.53.10.
Source port is 6000 and destination port is 8088 which use the TCP protocol...
62.47.147.4 - Found attack from 62.47.147.4.
=>Found attack from 62.47.147.4.
Use the ICMP protocol.
...
116.226.86.109 - Found attack from 116.226.86.109
=>Found attack from 116.226.86.109.
Source port is 37338 and destination port is 20279 which use the TCP protocol...
125.65.112.217 - Found attack from 125.65.112.217.
=>Found attack from 125.65.112.217.
Source port is 6000 and destination port is 8000 which use the TCP protocol....
78.38.206.145 - Found attack from 78.38.206.145.
=>Found attack from 78.38.206.145.
Source port is 6956 and destination port is 22 which use the TCP protocol.
...
61.160.216.187 - Found attack from 61.160.216.187.
=>Found attack from 61.160.216.187.
Source port is 6000 and destination port is 7212 which use the TCP protocol....
60.172.229.11 - Found attack from 60.172.229.11.
=>Found attack from 60.172.229.11.
Source port is 6000 and destination port is 2967 which use the TCP protocol....
61.139.105.163 - has been scanning my ip for the past 4 days.......
No.001 Sun, 2009-04-19 07:29:19 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.002 Sun, 2009-04-19 07:29:20 - TCP Packet - Source:61.139.105.163 Desti...
61.139.54.94 - Intrusion.Win.MSSQL.worm.Helkern!
07/05/2009 11:19:17 UDP from 61.139.54.94 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern...
219.159.228.211 - Intrusion.Win.MSSQL.worm.Helkern!
07/05/2009 01:24:53 UDP from 219.159.228.211 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern
...
218.75.199.50 - Intrusion.Win.MSSQL.worm.Helkern!
07/05/2009 11:26:56 UDP from 218.75.199.50 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern...
61.160.217.15 - Port Scanning
This group or person is constantly scanning my ports. Who are they, and what can I do to stop them?...
202.103.179.72 - Attacking my Computer - Data Theft
This IP Address is contineously attacking my computer. I receives alert by Firewall. It tries to send email without my knowledge, Data are stolen, Password theft and also hangs my PC. Be aware of this...
202.72.245.171 - Attacking my Computer - Data Theft
This IP Address is contineously attacking my computer. I receives alert by Firewall. It tries to send email without my knowledge, Data are stolen, Password theft and also hangs my PC. Be aware of this...
218.75.199.50 - Intrusion.Win.MSSQL.worm.Helkern!
Intrusion.Win.MSSQL.worm.Helkern! Attacker's IP address: 218.75.199.50. Protocol/service: UDP on local port 1434...
117.21.249.75 - 117.21.249.75
trying to gain access.
kernel: Intrusion detected from 117.21.249.75. Source port is 15070, and destination port is 22 which use the TCP protocol.
sneaky china man at it again....
202.99.11.99 - Intrusion.Win.MSSQL.worm.Helkern
22/4/2009 18:00:41 Intrusion.Win.MSSQL.worm.Helkern 202.99.11.99 UDP 1434...
202.99.11.99 - Intrusion.Win.MSSQL.worm.Helkern
22/4/2009 18:00:41 Intrusion.Win.MSSQL.worm.Helkern 202.99.11.99 UDP 1434...
61.147.107.56 - Multiple tries on port 2967
For the past few weeks this IP has been trying to enter our network via port 2967....
218.75.199.50 - Helkern Attack
Intrusion.Win.MSSQL.worm.Helkern! Attacker's IP address: 218.75.199.50. Protocol/service: UDP on local port 1434....
94.240.205.63 - instrusion win MSSQL worm helkern
94.240.205.63
instrusion win MSSQL worm helkern
instrusion win MSSQL worm helkern
instrusion win MSSQL worm helkern
instrusion win MSSQL worm helkern
instrusion win MSSQL worm helkern
instrusion...
24.97.211.83 - 24.97.211.83 Tried to login to Server
24.97.211.83 attempted to gain access to our Windows server through port 17270 15 times with the username "manager". ...
62.68.77.131 - Router reports repeated PORT SCAN attemps
Repeated PORT SCAN attempts from IP 61.139.105.163 , started Wed, 2009-04-01 19:23:43 Seems to be daily, two at a time at 1 second intervals.
Attempts to report abuse rejected by
MAILER-DAEMON@tfol....
more than 5 times per day...
more than 5 times per day...
24.94.153.165 - Attempted Connection
I followed the google map and found it coming from a house in the middle of what looks like a pasture well off the road. Just since yesterday there has been 31 \\\"connection attempts\\\" on my machin...
24.94.153.165 - Attempted Connection
IP 24.94.153.165
Connection Attempt
This person is in Parrish, Fla that's practically in my own backyard! SHEESH! They are EVERYWHERE!!...
62.173.6.172 - Unauthorized traffic to DMZ server
High Traffic Deny to DMZ server who is global nat with filtered ports on inbound and outbound.GMT +2.No abuse email only this is given on ripe.net chris@telemail.com.mt.Sended complain about this traf...
139.169.92.144 - Somebody is scanning your computer.
Somebody is scanning your computer.
Your computer's TCP ports:
22, 110, 1723, 265 and 443 have been scanned from 139.169.92.144....
218.98.106.53 - Detected:Intrusion.Win.MSSQL.worm.Helkern
1/4/2009 14:36:47 Intrusion.Win.MSSQL.worm.Helkern 218.98.106.53 UDP 1434
...
218.23.37.51 - Detected:Intrusion.Win.MSSQL.worm.Helkern
1/4/2009 14:35:46 Intrusion.Win.MSSQL.worm.Helkern 218.23.37.51 UDP 1434
...
202.99.11.99 - Detected: Intrusion.Win.MSSQL.worm.Helkern
31/03/2009 7:39:26 PM UDP from to local port 1434 Detected: Intrusion.Win.MSSQL.worm.Helkern...
202.99.11.99 - Detected: Intrusion.Win.MSSQL.worm.Helkern
31/3/2009 15:14:52 Intrusion.Win.MSSQL.worm.Helkern 202.99.11.99 UDP 1434
...
202.99.11.99 - Detected: Intrusion.Win.MSSQL.worm.Helkern
31/3/2009 15:14:52 Intrusion.Win.MSSQL.worm.Helkern 202.99.11.99 UDP 1434
...
202.99.11.99 - Detected: Intrusion.Win.MSSQL.worm.Helkern
31/3/2009 15:14:52 Intrusion.Win.MSSQL.worm.Helkern 202.99.11.99 UDP 1434
...
59.173.247.106 - Alert
31/3/2009 15:37:54 Intrusion.Win.MSSQL.worm.Helkern 59.173.247.106 UDP 1434
...
An intrusion attempt on my computer was blocked by my firewall from 61.139.105.163...
222.215.230.49 - Repeated Malware Probe- MyDoom in
I repeatedly get firewall alerts that MyDoom in under this IP address is trying to probe my computer and attacking it. 222.215.230.49 at port 12200 is continuously trying to up link and probe my compu...
124.161.72.45 - Trying to attack my system
Today my Internet security system warned me that a Pc from this IP address was trying to attack my system, unsuccessfully for sure....
77.202.138.87 - firewall intrusion
this ip french ip 77.202.138.87 IS SCANNING MY PORT , NO LUCK , VOULEZ VOUS COUCHE AVEC MOI........:))))))))))...
222.181.10.211 - Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 219.138.39.22 to local port 1434
3rd time at least this week...
86.127.74.27 - firewall intrusion
this ip 86.127.74.27 is trying to break through my firewall, no success, so if you see this ip is from SIBIU - ROMANIA......, SOMEBODY STOP AND HACK THIS GUY, HE DESERVE IT.......
61.139.105.163 - Waht can be done te stop 61.139.105.163
PROBLEMS PC Bilgium.
is scanning port on my firewall twice
or more a day for past 4&5 weeks
waht can be done?????????...
221.232.52.19 - Network Attack From Local port 1434
Network Attack From Local port 1434, im using KIS 2009....
202.99.11.99 - constant attack
UDP from 202.99.11.99 to local port 1434
Detected: Intrusion.Win.MSSQL.worm.Helkern
...
61.139.54.94 - constant attack
UDP from 61.139.54.94 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern...
124.161.72.45 - Intrusion attempt blocked
Port Scan by IP. 61.139.105.163 Is trying to scan my port,. My firewall is stopping it. This is several attempts by this IP....
82.11.209.72 - inbound probes as soon as I turn on computer; very alarming
pesky and annoying! Help!...
64.61.184.210 - Scanning of computer ports by 64.61.184.210
Received firewall alert that my computer ports were being scanned by 64.61.184.210. I looked up this IP address and its location is Brooklyn, New York....
61.139.105.163 - Scanned us also - firewall blocked.
Scanned our entire firewall IP with 10 counts on each port. Firewall blocked the attack. There might be more attacks in the future however....
61.139.105.163 - 61.139.105.163 is scanning ports
61.139.105.163 is scanning ports at least twice daily. Scanning interrupted by Firewall...
86.127.74.54 - firewall intrusion ip source port1403
this romanian sucker thinks that he could enter into my computer by ths IP 86.127.74.54 SIBIU-ROMANIA, YOU SUCKK MAN!!!!!!...
189.70.92.83 - firewall intrusion
this brazilian guy is trying to scan my ports so this is his IP 189.70.92.83 JABOAT BRAZIL , go to work coffee man........!!!!!!!...
60.173.12.43 - firewall intrusion port 6000
this ip 60.173.12.43 HEFEI CHINA is trying hard to enter into my computer , no luck for him , but is trying harder and harder... somebody shut him down .......
222.164.122.100 - Blocked Virous (Norton) From this Ip
(222.164.122.100)
Report: 222.164.122.100
Risk name: Nmap Null Scan
Risk Level: Medium [x][x][]
Default Action: Block
Action Taken: Block
Attacking computer: 222.164.122.100, 3208
Traffic Dis...
222.187.221.88 - Inbound TCP Connection Atempt Blocked by Fire Wall
Repeatedly attempting to get through my fire wall....
221.194.46.172 - Inbound TCP Connection Atempt Blocked by Fire Wall
Repeatedly attempting to get through my fire wall....
93.177.132.139 - Intrusion.Win.MSSQL.worm.Helkern
my fierwell get hem 3 or 4 times what can i do to stop hem ...
119.96.1.128 - TCP Syn/Fin packet dropped
02/27/2009 03:42:08.704 - Alert - Network Access - TCP Syn/Fin packet dropped - 119.96.1.128, 1500, X1 - xxx.xxx.xxx.xxx, 25 - TCP Flag(s): URG ACK SYN FIN
This email was generated by: SonicOS ...
97.87.114.250 - Multiple access attempts
Norton has notified me of several attempts of this IP trying to access lsass.exe...
61.153.58.189 - this ip tried to hack on me
hi
this ip address tried several times to hack on my computer i hope you will find a solution thanks alot...
60.191.104.242 - Detected: Intrusion.Win.MSSQL.worm.Helkern
UDP from this IP address to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern...
82.11.209.72 - Malware My Doom In
These inbound malware probes just bug me. I have received hundreds all captured by by F-Secure software. I generally get 6/7 per day. ...
202.99.11.99 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Detected: Intrusion.Win.MSSQL.worm.Helkern
Keep receiving this message from KAS 2009 14/02/2009 UDP from this IP to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.......
69.247.50.35 - Malicious Toolkit Variant Activity
Risk name-
HTTP Malicious Toolkit Variant Activity
High Risk
An intrusion attempt was blocked at 12/02/2009 2:22:18 PM
Attacking computer: A9B519AB99 (123.2.37.228, 1695)
Had this h...
170.210.60.253 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern! Attacker's from this ip address Protocol/service: UDP on local port 1434. ...
61.153.58.189 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern! Attacker\'s this IP address:. Protocol/service: UDP on local port 1434...
218.98.106.33 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern! Attacker's this IP address:. Protocol/service: UDP on local port 1434...
201.223.66.253 - Ataque de red
ataque de red intrusion.win.LSASS.exploit.TCP desde esta IP al puerto local 135...
201.223.43.253 - Ataque de red
ataque de red intrusion.win.LSASS.exploit.TCP desde esta IP al puerto local 135...
201.223.99.176 - Ataque de red
ataque de red intrusion.win.LSASS.exploit.TCP desde esta IP al puerto local 135...
219.139.208.38 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Protocol - UDP Port - 1434 Intrusion.Win.MSSQL.Worm.Helkern......
61.139.54.94 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Protocol - UDP Port - 1434 Intrusion.Win.MSSQL.Worm.Helkern...
195.24.78.186 - tried getting in my computer
tried getting in my computer and more info on the link to them....[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Whois qu...
58.53.128.68 - gren
Wow vonderfull! http://www.twine.com/user/arianaqqq
http://www.last.fm/user/Stevendsae/journal/2009/01/28/2ftz0t_today
http://www.lastfm.ru/user/Aaliyahfdv/journal/2009/01/25/2fhva4_sitemap
http://...
202.99.11.99 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern! Attacker\'s from this ip address. Protocol/service: UDP on local port 1434...
202.99.11.99 - Detected: Intrusion.Win.MSSQL.worm.Helkern
intrusion.Win.MSSQL.worm.Helkern! Attacker from this IP. Protocol/service: UDP on local port 1494...
58.82.189.34 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern! Attacker's from this ip Protocol/service: UDP on local port 1434....
58.20.154.23 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern! Attacker\\\'s from this ip Protocol/service: UDP on local port 1434....
82.228.81.59 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern! Attacker\'s from this ip Protocol/service: UDP on local port 1434....
92.82.101.153 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Intrusion.Win.MSSQL.worm.Helkern! Attacker's from this ip Protocol/service: UDP on local port 1434. ...
219.139.130.139 - worm helkern attack
network attack on my computer from this ip\"s 219.139.130.139;202.99.11.99;117.103.192.49(vietnam) . . . , always on port 1434 . . ....
202.99.11.99 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Keep receiving this message from KAS 2009 02/02/2009 UDP from this IP to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.......
61.177.196.226 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Keep receiving this message from KAS 2009 02/02/2009 UDP from this IP to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.......
219.139.130.139 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Keep receiving this message from KAS 2009 02/02/2009 UDP from 61.153.58.189 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.......
218.75.199.50 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Keep receiving this message from KAS 2009 02/02/2009 UDP from 61.153.58.189 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.......
59.81.64.229 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Keep receiving this message from KAS 2009 02/02/2009 UDP from 61.153.58.189 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.......
222.215.24.77 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Keep receiving this message from KAS 2009 02/02/2009 UDP from 61.153.58.189 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.......
87.118.120.71 - Kasperspy Internet Security Reporting worm HELKERN
Keep receiving this message from KAS 2009
01/02/2009 16:52:54 UDP from 61.153.58.189 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern...
82.165.45.155 - Attempted to access computer via ports 5901-5909
This IP sent TCP packets to ports 5901 thru 5909. Firewall reported as DOS and rejected...
117.103.192.49 - 117.103.192.49
UDP from 117.103.192.49 to local port 1434 Absent Detected: Intrusion.Win.MSSQL.worm.Helkern ...
218.75.199.50 - helkern worm intrusion from ip 218.75.199.50
helkern worm intrusion from ip 218.75.199.50 was detected. This is not the first time from this ip. ...
76.74.156.142, 8 - HTTP Malicous Toolkit Download Activity
It did not do anything but it said on my firewall that attack was blocked and the risk level was high, i also checked the IP and it came back to serverbeach in los angelas california
the destinatio...
76.74.156.142, 8 - HTTP Malicous Toolkit Download Activity
It did not do anything but it said on my firewall that attack was blocked and the risk level was high, i also checked the IP and it came back to serverbeach in los angelas california
the destinatio...
61.139.93.68 - Detected: Intrusion.Win.MSSQL.worm.Helkern
Detected: Intrusion.Win.MSSQL.worm.Helkern
UDP from 61.139.93.68 to local port 1434
...
83.233.194.19 - tcp flags bad combine attack
network attack intrusion generic tcp flags bad combine attack
ip 83.233.194.19...
222.46.9.7 - Illegal access
Tried to access my computer while I was on the internet. Firewall intercepted and blocked the illegal access....
174.133.5.202 - EXPLOIT OpenSSL ASN.1 Deallocation Attack
01/11/2009 04:51:19.350 - IPS Prevention Alert: EXPLOIT OpenSSL ASN.1 Deallocation Attack, SID: 4822, Priority: Medium - 174.133.5.202, 48274, WAN - 192.168.100.10, 443, LAN -
The LAN i...
88.80.7.82 - Port Scan
Hy. somebody scanning my computer and the firewall show's everdy day 2-3 attack from this ip 88.80.7.82, who is this or what can i do? someone know the answer?:D...
61.132.233.14 - worm. attack on my computer
1/6/2009 11:32:21 AM Intrusion.Win.MSSQL.worm.Helkern 61.132.223.14 UDP 1434...
208.78.69.70 - Every day scan
Every day scan my computer. My proxy alert: input on 88.80.7.82 and redirect to https://208.78.69.70...
219.133.37.42 - DOS MS-SQL Slammer Worm
This IP Address was responisble for a DOS MS-SQL Slammer Worm attack on my network. However, my firewall caught the attack and I do not this it got through. However, it coincided with other suspicious...
202.108.123.27 - Possible Dos HGOD SynKiller Flooding
This IP Address was responisble for a Possible Dos HGOD SynKiller Flooding attack on my network. However, my firewall caught the attack and I do not this it got through. However, it coincided with oth...
88.80.7.82 - 88.80.7.82. scanning my tcp ports
firewall alert shows 88.80.7.82. scanning my tcp ports.
is this a case for concern?
who is this ?why the scan?
...
58.42.234.135 - Kaspersky Internet security alert: UDP от(from) ***.***.***.*** на локальный порт(to local port) 1434 Intrusion.Win.MSSQL.worm.Helkern
оÑ(from) : 61.132.223.14 (202.99.11.99) (217.218.234.3) (58.42.234.135)(59.173.247.106)(221.233.242.4) (221.233.242.4) (209.42.59.22)
(202.101.165.202)...
84.19.184.33 - i am being attacked by the ip .
dec 24 21:17:41
kernel: PORT SCANNER ATTACK detected from 84.19.184.33. Source port is 1795, and destination port is 58755 which use the TCP protocol. ...
218.71.136.107 - Persistent attacks !
Persiste attacks on port 1434
STOOOOOOOOOOOOOOOP !!!!!
I will fill a complain to chinese government...
218.10.111.106 - IP 218.10.111.106 Tops Firewall Connection Attempts...
Mostly 9080 and 8090 TCP sync packets which my firewall blocked. Added entire net range class to my IP blocked rules. Note: Those people without a firewall should buy one to prevent computer issues......
218.10.111.106 - butt wipe keeps tripping my firewall
This address keeps tripping MAJOR SECURITY violation as well as repeated port scans (minor) as often as every 2-3 minutes most nights it's getting real annoying!...
persistent attacs...
persistent attacs...
218.75.199.50 - Intrusion.Win.MSSQL.worm.Helkern
Detected network attack Intrusion.Win.MSSQL.worm.Helkern 218.75.199.50...
91.89.249.158 - Intrusion.Win.DCOM.exploit
11.12.2008 18:47:29 TCP von 91.89.249.158 auf lokalen Port 135 Nicht vorhanden Gefunden: Intrusion.Win.DCOM.exploit
...
91.89.14.142 - Intrusion.Win.DCOM.exploit
11.12.2008 18:47:29 TCP von 91.89.14.142 auf lokalen Port 135 Nicht vorhanden Gefunden: Intrusion.Win.DCOM.exploit...
91.89.46.49 - Intrusion.Win.DCOM.exploit
11.12.2008 18:14:58 TCP von 91.89.46.49 auf lokalen Port 135 Nicht vorhanden Gefunden: Intrusion.Win.DCOM.exploit
...
91.89.114.230 - Intrusion.Win.DCOM.exploit
11.12.2008 18:11:29 TCP von 91.89.114.230 auf lokalen Port 135 Nicht vorhanden Gefunden: Intrusion.Win.DCOM.exploit
...
91.89.102.215 - Intrusion.Win.DCOM.exploit
11.12.2008 18:11:29 TCP von 91.89.102.215 auf lokalen Port 135 Nicht vorhanden Gefunden: Intrusion.Win.DCOM.exploit
...
91.89.190.224 - Intrusion.Win.DCOM.exploit
11.12.2008 18:11:29 TCP von 91.89.190.224 auf lokalen Port 135 Nicht vorhanden Gefunden: Intrusion.Win.DCOM.exploit...
91.89.51.189 - Intrusion.Win.DCOM.exploit
11.12.2008 18:47:28 TCP von 91.89.51.189 auf lokalen Port 135 Nicht vorhanden Gefunden: Intrusion.Win.DCOM.exploit...
123.232.124.244 - tried to access SSH a restricted port on server.
user denied access by firewall, firewall used was www.fs-security.com...
87.30.69.11 - tried to access ssh closed port on system
firewall alerted to attemt to access ssh but was rejected by firewall. firewall source used Firestarter for Linux http://www.fs-security.com...
221.233.242.4 - Daily intrusion attempts Win.MSSQL.worm.Helkern
Been getting attempts to hack in nightly four nights in a row around 21:00 PST. Kaspersky is catching it each time. On a dynamic IP DSL line....
12/6/2008 11:38:29 AM Intrusion.Win.MSSQL.worm.Helkern! IP-Adresse des Angreifers: 221.233.242.4. Protokoll/Dienst: UDP auf lokalem Port 1434. Zeit: 12/6/2008 11:38:29 AM...
12/6/2008 11:38:29 AM Intrusion.Win.MSSQL.worm.Helkern! IP-Adresse des Angreifers: 221.233.242.4. Protokoll/Dienst: UDP auf lokalem Port 1434. Zeit: 12/6/2008 11:38:29 AM...
218.22.244.45 - Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 218.22.244.45 to local port 1434
I keep on getting alerts from Kaspersky about this intrusion. Not only this but several intrusion and I'm getting very slow internet connection. I clean this with adaware but keeps coming bacl....
206.246.240.79 - Tons of Spam Packets
From my WatchGuard Firebox II the Traffic Monitor alerts me that IP:206.246.240.79
Host Name: rackhosters.com
sending tons of spam packets 24hours/day for months.
I have screen shots from my Traffi...
76.12.58.197 - Tons of Spam Packets
From my WatchGuard Firebox II I get alerts from WatchGuard Traffic Monitor that the following IP: 76.12.58.197
Host Name: mail.internetseer.com
is sending tons of spam packets 24hours/day for months...
76.12.58.197 - Tons of Spam Packets
From my WatchGuard Firebox II I get alerts from WatchGuard Traffic Monitor that the following IP: 76.12.58.197
Host Name: mail.internetseer.com
is sending tons of spam packets 24hours/day for months...
Firewall : running
------------------
Network attacks detected: 4
Time of last attack: 25.11.2008 13:57:07
Popups: 0
Banners: 5
Start time: 25.11.2008 7:23:57
Duration: 07:01:17
Network at...
195.154.194.179 - machine scan
my firwall reported that this ip have been scanning my computer ports...
11/22/2008 6:30:02 PM Intrusion.Win.MSSQL.worm.Helkern 218.84.7.20 UDP 1434...
11/22/2008 7:50:04 PM Intrusion.Win.MSSQL.worm.Helkern 61.139.76.34 UDP 1434...
11/22/2008 8:34:06 PM Intrusion.Win.MSSQL.worm.Helkern 218.75.199.50 UDP 1434
...
190.96.4.170 - Intrusion.Win.LSASS
21/11/2008 11:21:27 Intrusion.Win.LSASS.ASN1-kill-bill.exploit 190.96.4.170 TCP 445
...
202.99.11.99 - Intrusion.Win.MSSQL.worm.Helkern
21/11/2008 11:32:20 Intrusion.Win.MSSQL.worm.Helkern 202.99.11.99 UDP 1434
...
11/20/2008 6:51:47 PM Intrusion.Win.MSSQL.worm.Helkern 198.87.3.30 UDP 1434...
69.127.17.158:5 - 11/19/2008 2:10:02 AM Detected Reverse TCP Desynchronization attack 69.127.17.158:52350 7 TCP
11/19/2008 2:10:02 AM Detected Reverse TCP Desynchronization attack 69.127.17.158:52350 TCP ...
11/19/2008 12:29:47 AM Detected DNS cache poisoning attack 192.168.0.1:53 UDP
This has happened 5 times in 1 minute various days my firewall log will report this and it will happen 5 times on every ...
211.95.78.70 - Firewall TCP_IN
Time: Sat Nov 15 07:06:30 2008 +0000IP: 211.95.78.70 (CN/China/-)Hits: 11Blocked: temporarily for 3600 seconds Sample of block hits:Nov 15 07:06:13 server1 kernel: Firewall: *TCP_IN Blocked* IN=eth0 O...
211.232.193.22 - tried to access Telenet service
Firewall alerted to possible Telnet access. This is a closed port...
218.71.136.106 - Intrusion.Win.MSSQL.worm.Helkern
UDP from 218.71.136.106 on local port 1434 - Found: Intrusion.Win.MSSQL.worm.Helkern - on 14.11.2008, 12:22:55...
202.99.11.99 - 14.11.2008 11:40:52 Detected: Intrusion.Win.MSSQL.worm.Helkern Absent UDP from 202.99.11.99 to local port 1434
firewall detected...
80.16.1.225 - Intrusion.Win.MSSQL.worm.Helkern
14/11/2008 14:31:50 Intrusion.Win.MSSQL.worm.Helkern 80.16.1.225 UDP 1434...
221.233.242.4 - Intrusion.Win.MSSQL.worm.Helkern
14/11/2008 14:07:22 Intrusion.Win.MSSQL.worm.Helkern 221.233.242.4 UDP 1434...
221.233.242.4 - tried to access port 1434 ms-sql-m
attempt failed. port is closed to public access...
62.143.242.62 - Intrusion.Win.MSSQL.worm.Helkern
13/11/2008 12:02:00 Intrusion.Win.MSSQL.worm.Helkern 62.143.242.62 UDP 1434...
61.139.54.94 - Intrusion.Win.MSSQL.worm.Helkern
13/11/2008 12:02:00 Intrusion.Win.MSSQL.worm.Helkern 61.139.54.94 UDP 1434...
125.65.165.132 - 115 hits in 12 hours
Since my last report this guy has been trying to get in permanently. 115 hits in a 12 hour period is just recklessly stupid....
58.20.154.23 - Intrusion.Win.MSSQL.worm.Helkern
11/11/2008 13:53:06 Intrusion.Win.MSSQL.worm.Helkern 58.20.154.23 UDP 1434...
4.79.142.206 - 4.79.142.206 attempting to hack PC
Part of log.
TCP Packet - Source:4.79.142.206,63092 Destination:87.227.XX.XX,445 - [DOS]
Sun, 2008-11-02 04:23:29 - TCP Packet - Source:4.79.142.206,63092 Destination:87.227.XX.XX,443 - [DOS]
Sun, ...
125.65.165.132 - Router firewall prevented hacker
Have been experiencing numerous disconnects from WAN, every 30 minutes or so. Router firewall reports that 125.65.165.132 is attempting to access port 3128....
116.17.128.254 - port attacked
my firewall popped up saying that ip 116.17.128.254 attacked port scanning....
80.64.65.67 - Tons of Spam Packets
The WatchGuard \\\\\\\\\\\\\\\"Traffic Monitor\\\\\\\\\\\\\\\" and \\\\\\\\\\\\\\\"HostWatch\\\\\\\\\\\\\\\" from my Firebox II alerts me and shows that the above IP is sending spam packets to port25....
80.64.65.67 - Tons of Spam Packets
The WatchGuard \\\\\\\"Traffic Monitor\\\\\\\" and \\\\\\\"HostWatch\\\\\\\" from my Firebox II alerts me and shows that the above IP is sending spam packets to port25.
I have blocked port25 on my Fi...
211.103.139.196 - Intrusion.Win.MSSQL.worm.Helkern
10/11/2008 20:36:57 Intrusion.Win.MSSQL.worm.Helkern 211.103.139.196 UDP 1434...
59.173.247.106 - IntrusionWin.MSSQL.worm.Helkern
10/11/2008 12:40:59 Intrusion.Win.MSSQL.worm.Helkern 59.173.247.106 UDP 1434...
202.99.11.99 - IntrusionWin.MSSQL.worm.Helkern
10/11/2008 14:27:09 Intrusion.Win.MSSQL.worm.Helkern 202.99.11.99 UDP 1434...
218.75.199.50 - IntrusionWin.MSSQL.worm.Helkern
10/11/2008 19:25:56 Intrusion.Win.MSSQL.worm.Helkern 218.75.199.50 UDP 1434
...
124.11.188.172 - port scan
3 scans from 218.10.111.106 today
fire wall reported\"
Somebody is scanning your computer.
Your computer\'s TCP ports:
8090, 9090, 9000, and 988 have been scanned from 218.10.111.106.....
218.10.111.106 - Port Scans
My firewall reports:
Somebody is scanning your computer.
Your computer's TCP ports have been scanned from 218.10.111.106....
218.75.199.50 - Detected: Intrusion.Win.MSSQL.worm.Helkern
UDP from 218.75.199.50 to local port 1434
Detected: Intrusion.Win.MSSQL.worm.Helkern...
77.127.111.220 - My Firewall blocked attempt of not authorised access to my computer.
My Firewall blocked attempt of not authorised access to my computer....
Detected network attack Intrusion.Win.MSSQL.worm.Helkern 218.75.199.50...
Detected network attack Intrusion.Win.MSSQL.worm.Helkern 218.75.199.50...
218.10.111.106 - 218.10.111.106 constant attempts to access
This host keeps trying to access ports 8090, 9090, 9000, and 9788 -- every 15 minutes or so -- been going on for days, maybe more. My firewll keeps blocking them, but it's really annoying. There are...
212.107.116.232 - not open site
i want open malayalampadam.com when i click malayalam padam there was found ip212.107.116.232 please make correct my web malayalampadam.com pleaseeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee...
117.101.128.131 - Port scan
2008-10-20 19:22:37 Intrusion.Win.MSSQL.worm.Helkern 117.101.128.131 UDP 1434
...
200.16.6.89 - Please take it away !
Seriously putting my internet ping high ! I cant even go onto one webpage for like 5 minutes and i have cable ! He is attacking my computer malicously !...
65.207.183.126 - Found PortScanner attack from 65.207.183.126 in port 3502
Multiple attacks on my firewall log...
222.187.221.83 - Found Syncflood attack from 222.187.221.83 in port 8000
Multiple attacks on my firewall log...
19.10.2008 2:17:18 Intrusion.Win.MSSQL.worm.Helkern! IP-адÑÐµÑ Ð°ÑакÑÑÑего: 218.75.199.50. ÐÑоÑокол/ÑеÑвиÑ: UDP на локалÑнÑй поÑÑ 1434. ÐÑемÑ: 19.10.2008...
123.220.128.234 - Intrusion.Win.MSSQL.worm.Helkern!
2008-10-19 00:50:11 Intrusion.Win.MSSQL.worm.Helkern! Attacker\'s IP address: 123.220.128.234. Protocol/service: UDP on local port 1434. Time: 2008-10-19 00:50:11...
75.130.210.48 - rapid fire pinging
zone alarm was constantly warning of ping attempts from this site - nine in about 15 seconds once the internet came on line....
203.123.205.107 - 218.10.111.106 multiple scans
scans about every 2 min and attempts to reconfigure my setting on my computer.
Also seems to be interfering with download speeds. seems to bog down the system....
88.109.67.30 - 218.10.111.106 multiple scans
scans about every 2 min and attempts to reconfigure my setting on my computer.
Also seems to be interfering with download speeds. seems to bog down the system....
218.10.111.106 - 218.10.111.106 multiple scans
scans about every 2 min and attempts to reconfigure my setting on my computer.
Also seems to be interfering with download speeds. seems to bog down the system....
69.247.50.35 - HTTP Malicious Toolkit Variant Activity
AT 14:20 EST, this ip made in attempt to attack my computer. Not too familiar with this type of stuff, but this kind of activity pissing me off....
24.84.0.21 - port scanning
Sence 9:09 AM today local time from this IP location I've recieved 13 port scannings...my firewall gone crazy! ...
195.93.21.104 - cant get on websites because of this ip address
this ip address is stopping me from getting on a website it is telling me firewall blocked and the ip address could you please help...
195.93.21.104 - cant get on websites because of this ip address
this ip address is stopping me from getting on a website it is telling me firewall blocked and the ip address could you please help...
125.65.165.132 - Another scan of 8080
Looks like our Squid-loving Chinaman is back again, this time he's trying my port 8080 (obviously got tired of trying 8800 & 3128). Not as persistent as last time, this is the first probe in days....
210.41.224.178 - 125.65.165.132 port scans
Somebody is scanning your computer.
Your computer\\\\\\\'s TCP ports:
8800, 8000, 8080, and 8810 have been scanned from 125.65.165.132..
I have the ip blocked in the firewall, this port scan ...
218.10.111.106 - i get a warning about every 2 mins.
just keeps setting off my firewall warning system....
76.74.248.79 - attempted attck?
Norton came up and said they blocked this. Im kinda new to this so I dont really kow whats goin on. but yeah this is wierd...
66.115.189.83 - Scanning Ports
Picked up by BullGuard Firewall. Computer not infected but several ports attacked....
121.128.133.12 - this ip is trying to send me virus's
this ip is trying to send me virus\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\...
90.184.7.133 - nmap xmas scam report blocked by norton
norton was able to block this attck several times for me no damage was down to my system that i have noticed, yet....
222.180.37.14 - Attacking ports 7212 and 9788
Firewall reports hundreds of requests to ports 7212 and 9788 with large payloads...
125.65.165.132 - Blocked by BullGuard while scanning ports
No damage done as firewall very efficient. Just nuisance and intrusive....
88.80.7.82 - Scanning my computer
This one sometimes scans my computer...fortunatelly my firewall blocks him. Somebody knows what is it?
Why it do it? Can be avoided?...
116.5.84.251 - TCP Syn/Fin Packet
flagged by firewall
07/17/2008 10:39:10.592 - Alert - Network Access - TCP Syn/Fin packet dropped - 116.5.84.251, 37597, WAN - xxx.xxx.xxx.xxx, 25 - TCP Flag(s): ACK RST FIN...
38.107.160.113 - 78 port scans from 38.107.160.118 and 38.107.160.113
Repeated scanning of numerous ports from these two ip's....
213.165.183.88 - Unsuccessful Hacker but very annoying!!!!
I'm Tired of receiving firewall alerts from this one person all day.The duration so far has been 2 days. My firewall is picking up the risk name as "NMap Xmas Scan". The traffic description is TCP,44...
62.68.76.210 - Attacked every few minutes
Annoying! Attacks eveery few minutes! My norton stops it, but how can I prevent this happening?...
IP address and other addresses on the 65.55 subnet is accessing my server for no reason. Browing my store and adding items to the cart but without buying. clearly not someone casually browsing due to ...
194.254.215.11 - Detected Reverse TCP Desynchronization attack
6/19/2008 8:20:18 PM Detected Reverse TCP Desynchronization attack 194.254.215.11:8080...
4.79.142.206 - 4.79.142.206 attempting to hack PC
This IP has been port scanning and flooding my addy with Pings and attempted remote access for last 3 days. Firewall (Norton) blocking him/her....
83.136.13.230 - Performing NMap Null Scan
Several times now, my firewall has detected an NMap Null Scan coming from IP 83.136.13.230...
88.80.7.82 - again.
Detected 36895, 14340, 16415, 20480, 14348 port(s) scanning from 88.80.7.82.
Few times every day....
4.79.142.206 - Firewall alerts
4.79.142.206 has been hitting on my computer for almost 30 times in the span of about 5 minutes. Think he\'s up to no good.
...
72.194.218.77 - tried to access my computer
i was surfing when my firewall told me this person was trying to use my computer...
4.79.142.206 - do not know what he is up to
my firewall has blocked this address between 15.47.59- 18.41 28 for over three hours he has been trying to get into my computer...
top performing domains latest complaints new questions categories
Latest Questions
- Lots of attack on the router - He has enabled the wireless mode inside the box from shell and I cannot turn it off?
- Lots of attack on the router - He has enabled the wireless mode inside the box from shell and I cannot turn it off?
- Lots of attack on the router - He has enabled the wireless mode inside the box from shell and I cannot turn it off?
- Lots of attack on the router - He has enabled the wireless mode inside the box from shell and I cannot turn it off?
