61.139.105.163 is from China
An Internet Protocol address (IP address 61.139.105.163) is a numerical label that is allocated to a computer (can be any electronic device) which is part of a network (CHINANET Sichuan province network) that utilises the Internet Protocol. Every IP address does the following: (1) location addressing and (2) host or network interface identification.
e.g. 209.62.45.34 IPv4/IPv6 format for an IP Address, or maxmind.com for a website
Compare to another IP
| IP Address: | 61.139.105.163 |
|---|---|
| IP Address Country: | |
| IP Address Region: | 32 Sichuan |
| IP Address City: | Zigong |
| IP Postal Code | |
| IP Address Area Code | 0 |
| IP Metro Code | 0 |
| IP Address Latitude: | 29.3999996185 |
| IP Address Longitude: | 104.783302307 |
| IP Address ISP: | CHINANET Sichuan province network |
| Organisation: | CHINANET Sichuan province network |
| IP Address Proxy: | |
| IP Address Host: | 61.139.105.163 |
Map is loading...
We have 309 complaints about 61.139.105.163
Is 61.139.105.163 misbehaving (engaging in SPAM, brute-force, DOS attack, phishing, or other fraud? Report the abuser now!
View WHOIS information for 61.139.105.163[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net node-4]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html
inetnum: 61.139.105.128 - 61.139.105.191
netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
country: CN
admin-c: XS16-AP
tech-c: XS16-AP
mnt-by: MAINT-CHINANET-SC
changed: sxdong@mail.sc.cninfo.net 20010619
status: ASSIGNED NON-PORTABLE
source: APNIC
changed: hm-changed@apnic.net 20020827
person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
country: CN
changed: ipadmin@my-public.sc.cninfo.net 20030317
mnt-by: MAINT-CHINANET-SC
source: APNIC
[whois.apnic.net]
% [whois.apnic.net node-4]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html
inetnum: 61.139.105.128 - 61.139.105.191
netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
country: CN
admin-c: XS16-AP
tech-c: XS16-AP
mnt-by: MAINT-CHINANET-SC
changed: sxdong@mail.sc.cninfo.net 20010619
status: ASSIGNED NON-PORTABLE
source: APNIC
changed: hm-changed@apnic.net 20020827
person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
country: CN
changed: ipadmin@my-public.sc.cninfo.net 20030317
mnt-by: MAINT-CHINANET-SC
source: APNIC
15 Latest Attacks
89.108.127.160 - Site is a scam - filed under Fraud
one of the sites through this host, everingame.com has defrauded hundreds of users. http://www.scamb...
114.36.160.94 - mindless stuff - filed under Spam
Hacking attemps, spaming. He has inserted himeslf into our medical servicesrecipients. It has been r...
205.186.130.61 - email hijacking - filed under Hacking
This person has been logging into my gmail account and sent out spam emails to my entire contact lis...
202.104.197.118 - Attempted login to FTP - filed under Brute Force
Brute force attempts to log into my server FTP with the username "administrator."
A sim...
74.128.173.47 - Bet2day casino - filed under Spam
Same as the rest, spam mail every hour now on 3 of my emails. No way to unsubscribe and impossible t...
173.9.198.249 - website was hacked 2 days ago - filed under FTP Hacking
2 days ago from this ip several of our websites we're hacked by logging on to our ftp webhosting ac...
66.147.240.186 - This IP is trying to logon my website - filed under Brute Force
Website: http://www.iphonesp.com.br/
Page: /administrator/index.php
Description: There was an unsu...
94.183.53.255 - Attacking Google account - filed under Hacking
Someone recently tried to sign in to your Google Account, XXXXX. We prevented the sign-in attempt in...
67.205.111.248 - 184.107.157.130 - filed under Hacking
this site keeps port scanning my IP addresses. i have him blocked but clearly theres a problem with...
72.21.194.32 - Risky connection blocked - filed under Malware
Looks to me like 72.21.194.32 is a server leased from Amazon's cloud services server farm by someon...
74.128.173.47 - unsubscribe bet2day from Ryan Hardy - filed under Spam
no way to unsubscribe to their unwanted mail about bet2day; looks to me a kind of spam or other non...
178.33.224.175 - Continuous ICMP ping id-0 to all our public facing IP Addresses - filed under Firewall Alert
[00001] 2012-05-14 18:09:02 [Root]system-critical-00441: ICMP ping id=0! From 178.33.224.175 to 66.2...
92.38.199.150 - Subject: Good Day: Unsolicited, unsigned for 'loan/investment' spam from Russia - filed under Spam
Unsolicited spam from webmaster@arclip.ru -user17662
Received: from s6.cishost.ru ([92.38.199.150])...
2012/05/16 20:18:16 +0300 DEOCAMDATARDS computer IP-BLOCK 77.78.228.62 (Type: incoming)
2012/05/16 2...
More Attacks
125.45.109.166 - Tese guys keep scanning - filed under Port Scanning
these guys has been scanning my computer on a daily bases for the last week and i am really getting ...
208.73.210.29 - IP 208.73.210.29 - filed under Malware
The website is continuosly forcing itself to open on my pc.It is very aggresive and is blocked than...
41.237.250.253 - ALERT FROM GOOGLE - filed under Phishing
I RECEIVED AN ALERT FORM GOOGLE ABOUT THE IP 41.238.192.197 CORRESPONDING TO TDCR2-AFRINIC WHICH WAS...
94.76.244.149 - http://scotia-vehicle-inspection.co.uk/administrator/includes/pcl/ertzgz/14554421df23415d41523sqd/zerg45415eg/chmo.htm - filed under Phishing
fraud@antihotmail.com
------------------------------
http://scotia-vehicle-inspection.co.uk/adminis...
119.155.15.115 - Report spam - filed under Spam
Hello,
Below is a SPAM received by our system. It originated from your site, used an address referen...
61.9.214.65 - attempts scans several times a day - filed under Port Scanning
"Somebody is scanning your computer.
Your computer's TCP ports:
8080, 443, 1080, and 3128 have...
12.146.242.59 - dos attack from this address - filed under DDOS
12.146.242.59, port 80
DoS Attack: ACK Scan...
A connection was opened data was taken i think this address is being used by a hacker, a prolonged c...
184.172.173.227 - suspicious gmail login - filed under Hacking
I received a message from gmail that ip 184.172.173.227 logged into my email account with an unknown...
58.218.199.227 - Port Scanning - filed under Port Scanning
I am being port scanned numerous times per day for the last several months from this IP address. Ple...
24.189.170.184 - Roy Santoni Fraudulent Purchase Scam - filed under Fraud
Roy Santoni Fraud attempt to purchase bicycle related products. The transaction was odd and I google...
123.108.6.210 - Hacking MySQL server - filed under Hacking
123.108.6.98 - - [05/Feb/2012:05:06:25 +0000] "GET /muieblackcat HTTP/1.1" 404 269 &quo...
188.212.152.4 - SPAM REPORT VERY DANGEROUS - filed under SMTP Fraud
MANY SUB DOMAINS WITH THOUSANDS OF FRAUD MAIL EVERY DAY.
www. emagu .ro with many sub-domains
www. ...
69.164.214.223 - cheap shoes online - filed under HTTP Fraud
This is a great post. you got <a href="http://www.cheap-shoes-online.org" title=&quo...
115.249.45.19 - http://mail.orgltd.com/.cgi/secureform49.paypal.com/websdr.php - filed under Phishing
fraud@antihotmail.com
------------------------------
http://mail.orgltd.com/.cgi/secureform49.payp...
204.152.202.26 - Baby hackers - Opening & closing & opening & closing & opening ports - filed under SMTP Fraud
14/09/2010 05:58:28 AM Opened TCP/IP connection from 204.152.202.26,43237 to x.x.x.x,25
14/09/2010 ...
10.134.28.1 - DoS every minute 10.134.28.1 - filed under DDOS
Fri Jun 11 19:43:44 2010 1 Blocked by DoS protection 10.134.28.1
Fri Jun 11 19:44:56 2010 1 Blocke...
184.107.152.122 - Serinah Frederickson - filed under Fraud
I am trying to reach Serinah Frederickson with iweb technology and no one will give me a contact num...
220.161.111.118 - Illegal User Access on ssh - filed under Hacking
May 23 04:18:30 server sshd[6551]: (pam_unix) authentication failure; logname= uid=0 euid=0 tty=ssh ...
61.57.41.187 - Blocked on 3389 - filed under Hacking
This ip tried to access ms-wbt-server on tcp port 3389...
195.140.185.243 - Spam from contact@ecards.com - filed under Spam
We have had lots of spam coming from the email address contact@eCards.com.
after checking the hea...
85.27.84.117 - Game Server Attacks - filed under DDOS
The following IP (85.27.84.117) has been associated to trying to DDoS several game servers on Call o...
96.125.163.31 - http://vitworks.com/docs/management2/uk/management/financial - filed under Phishing
fraud@antihotmail.com
------------------------------
http://vitworks.com/docs/management2/uk/manage...
24.87.34.195 - Scanning and DOS attacking my ip - filed under Port Scanning
am receiving alot of dos attacks in all my ports on my router......
Domains in the same C Block

https://forms.us-cert.gov/report/index.php
Sun 2010-01-17 20:12:40 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:8888 droped
Sun 2010-01-17 20:12:43 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:1025 droped
Sun 2010-01-17 20:12:45 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:8081 droped
Tue 2010-01-19 06:32:10 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:1025 droped
Tue 2010-01-19 06:32:12 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:8081 droped
Tue 2010-01-19 22:06:16 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:8081 droped
Fri 2010-01-22 01:14:31 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:8118 droped
Fri 2010-01-22 01:14:33 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:8888 droped
Fri 2010-01-22 01:14:35 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:1025 droped
Fri 2010-01-22 01:14:38 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:8081 droped
Mon 2010-01-25 02:47:37 TCP flood From 61.139.105.163 port:12200 To 74.65.*.* port:8081 droped
first on: Thu, 2010-01-21 16:10:18
then again on: Fri, 2010-01-22 11:35:16
TCP Packet - Source:61.139.105.163 Destination:XX.XX.XX.XX
(my ip deleted for security reasons)
Someone stop this SOB. Does he not know China still has the death penalty?
[Tue Jan 19 04:53:27 2010] [error] [client 61.139.105.163] File does not exist: /var/www/html/fastenv
61.139.105.163 - - [19/Jan/2010:04:53:27 -0500] "GET http://proxyjudge1.proxyfire.net/fastenv HTTP/1.1" 404 295 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
Your computer's TCP ports:
808, 8118, 8888, and 8081 have been scanned from 61.139.105.163.- inetnum: 61.139.105.128 - 61.139.105.191
netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
country: CN
admin-c: XS16-AP
tech-c: XS16-AP
mnt-by: MAINT-CHINANET-SC
changed: sxdong@mail.sc.cninfo.net 20010619
status: ASSIGNED NON-PORTABLE
source: APNIC
changed: hm-changed@apnic.net 20020827
person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
country: CN
changed: ipadmin@my-public.sc.cninfo.net 20030317
mnt-by: MAINT-CHINANET-SC
source: APNIC
- http://www.ipillion.com/?ip=61.139.105.163&ipsubmit=by+IP
01/19/2010 08:45:19.848 Possible port scan dropped 61.139.105.163, 12200, WAN
17.01.2010 21:39:25 61.139.105.163 SCAN (50980, 10275, 38175, 38943, 39199, 33315, 14340)
14.01.2010 22:35:52 61.139.105.163 SCAN (50980, 10275, 38175, 38943, 39199, 14340)
07.01.2010 21:59:45 61.139.105.163 SCAN (50980, 10275, 38175, 38943, 39199, 33315, 14340)
07.01.2010 14:22:12 61.139.105.163 SCAN (50980, 10275, 38175, 38943, 33315, 14340)
in light of this week's news from Google, this may be a Chinese govt. site for all anybody knows
here's hoping their govt. is changed at the earliest possible date
61.139.105.163:12200
Today I have had 13 attemps on common ports and and attempt to have a go at my smtp server.
My Isp are unable to help me. Perhaps its now time for us all to get together and report this to the police as this is surely a breach of the computer missuse act !
Nmap is free to download.
Your computer's TCP ports:
80, 6588, 8000, and 808 have been scanned from 61.139.105.163 - netname: ZIGONG-SCINFO-GOV descr: Zigong Sciences Informations Academe descr: ZiGong,Sichuan descr: PR China person: Xiaodong Shi nic-hdl: XS16-AP e-mail: ipadmin@my-public.sc.cninfo.net address: No.72,Wen Miao Qian Str. address: Data Communication Bureau Of Sichuan Province address: Chengdu address: PR China phone: +86-28-6190785 fax-no: +86-28-6190641 https://isc.sans.org/ipinfo.html?ip=61.139.105.163
Is there anything that can be done?
Source port is 12200 and destination port is 9415 which use the TCP protocol.
Thu Jan 7 05:47:58 2010
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 9000 which use the TCP protocol.
Thu Jan 7 05:47:58 2010
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8080 which use the TCP protocol.
Thu Jan 7 05:47:58 2010
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8085 which use the TCP protocol.
Thu Jan 7 05:47:58 2010
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8088 which use the TCP protocol.
Thu Jan 7 05:47:58 2010
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8089 which use the TCP protocol.
Thu Jan 7 05:47:58 2010
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 3128 which use the TCP protocol.
Thu Jan 7 05:47:58 2010
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 9090 which use the TCP protocol.
Thu Jan 7 05:48:28 2010
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 1080 which use the TCP protocol.
Thu Jan 7 05:48:28 2010
TCP Packet - Source:61.139.105.163 Destination:192.168.0.98 - [PORT SCAN]
For over one month now I have been receiving TCP and UDP port scans along with probes to test for vulnerable services. I have reported this before but heard nothing back. This user has now made it to the first page of google ! http://www.google.co.uk/search?hl=en&source=hp&q=61.139.105.163&btnG=Google+Search&meta=&aq=null&oq=
The source IP for this traffic is 61.139.105.163
I have many hundred kilobytes of stored logs in .txt format if you should need them. I have found thousands of users complaining about the activity from this ip. If this continues to happen then I will be making a report to my ISP and the UK police force.
I look forward to your reply.
Stuart Epton
(BSC.Amiee) (MCSE) (MCP) (SECURITY+) (CCNA)
Network Security Engineer
T.R.S. Security L.T.D.
What is anoying me is that I am allways seing him in my log files and he seems to be able to send all this junk out with impunity.
I personaly dont think this is am infected/zombie machine as the attacks are to varied and often target recent vulns that have just been discovered. I feel like taking this issue to my ISP as this idiot's ISP obviosly doesnt give damb.
BTW - Its been well over a month now and I have 176 forms of attack including 536 full tcp port scans and several short udp scans.
Stuart.
Your computer's TCP ports:
6588, 8000, 8090, and 7212 have been scanned from 61.139.105.163- netname: ZIGONG-SCINFO-GOV descr: Zigong Sciences Informations Academe descr: ZiGong,Sichuan descr: PR China person: Xiaodong Shi nic-hdl: XS16-AP e-mail: ipadmin@my-public.sc.cninfo.net address: No.72,Wen Miao Qian Str. address: Data Communication Bureau Of Sichuan Province address: Chengdu address: PR China phone: +86-28-6190785 fax-no: +86-28-6190641 https://isc.sans.org/ipinfo.html?ip=61.139.105.163
Your computer's TCP ports:
7212, 8118, 8888, and 8081 have been scanned from 61.139.105.163-netname: ZIGONG-SCINFO-GOV descr: Zigong Sciences Informations Academe descr: ZiGong,Sichuan descr: PR China person: Xiaodong Shi nic-hdl: XS16-AP e-mail: ipadmin@my-public.sc.cninfo.net address: No.72,Wen Miao Qian Str. address: Data Communication Bureau Of Sichuan Province address: Chengdu address: PR China phone: +86-28-6190785 fax-no: +86-28-6190641 https://isc.sans.org/ipinfo.html?ip=61.139.105.163
Intrusion Detection for from IP 61.139.105.106
for more result about this ip see below link :http://www.ip-adress.com/whois/61.139.105.163
Your computer's TCP ports:
8090, 8000, 7212, and 8888 have been scanned from 61.139.105.163
-- inetnum: 61.139.105.128 - 61.139.105.191 netname: ZIGONG-SCINFO-GOV descr: Zigong Sciences Informations Academe descr: ZiGong,Sichuan descr: PR China person: Xiaodong Shi nic-hdl: XS16-AP e-mail: ipadmin@my-public.sc.cninfo.net address: No.72,Wen Miao Qian Str. address: Data Communication Bureau Of Sichuan Province address: Chengdu address: PR China phone: +86-28-6190785 fax-no: +86-28-6190641 country: CN changed: ipadmin@my-public.sc.cninfo.net 20030317 mnt-by: MAINT-CHINANET-SC source: APNIC ---- https://isc.sans.org/ipinfo.html?ip=61.139.105.163
Your computer's TCP ports:
1025, 8888, 8088, and 8081 have been scanned from 61.139.105.163. - inetnum: 61.139.105.128 - 61.139.105.191
netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
country: CN
changed: ipadmin@my-public.sc.cninfo.net 20030317
mnt-by: MAINT-CHINANET-SC
source: APNIC
----
https://isc.sans.org/ipinfo.html?ip=61.139.105.163
[17/Dec/2009 00:14:41] PORTSCAN firewall="" hostip="61.139.105.163" hostname="61.139.105.163" log="protocol: TCP, source: 61.139.105.163, destination: ***, ports: 9000, 3128, 8000, 9090, 8080, 8085, 8089, 8090, 6588, 9415, ..." time="Thu Dec 17 00:14:41 2009" username="not logged yet"
[17/Dec/2009 13:08:43] PORTSCAN firewall="" hostip="61.139.105.163" hostname="61.139.105.163" log="protocol: TCP, source: 61.139.105.163, destination: ***, ports: 9000, 3128, 8000, 80, 8080, 8085, 8089, 8090, 6588, 9415, ..." time="Thu Dec 17 13:08:43 2009" username="not logged yet"
[18/Dec/2009 10:00:13] PORTSCAN firewall="" hostip="61.139.105.163" hostname="61.139.105.163" log="protocol: TCP, source: 61.139.105.163, destination: ***, ports: 9000, 1080, 3128, 80, 8080, 8085, 8088, 8090, 6588, 2301, ..." time="Fri Dec 18 10:00:13 2009" username="not logged yet"
[18/Dec/2009 22:01:13] PORTSCAN firewall="" hostip="61.139.105.163" hostname="61.139.105.163" log="protocol: TCP, source: 61.139.105.163, destination: ***, ports: 1080, 3128, 8000, 80, 8080, 8085, 8088, 8089, 6588, 2301, ..." time="Fri Dec 18 22:01:13 2009" username="not logged yet"
[19/Dec/2009 15:00:35] PORTSCAN firewall="" hostip="61.139.105.163" hostname="61.139.105.163" log="protocol: TCP, source: 61.139.105.163, destination: ***, ports: 9000, 1080, 3128, 80, 9090, 8080, 8088, 6588, 9415, 2301, ..." time="Sat Dec 19 15:00:35 2009" username="not logged yet"
[20/Dec/2009 09:34:54] PORTSCAN firewall="" hostip="61.139.105.163" hostname="61.139.105.163" log="protocol: TCP, source: 61.139.105.163, destination: ***, ports: 9000, 1080, 8000, 80, 9090, 8080, 8089, 8090, 9415, 2301, ..." time="Sun Dec 20 09:34:54 2009" username="not logged yet"
[20/Dec/2009 23:41:39] PORTSCAN firewall="" hostip="61.139.105.163" hostname="61.139.105.163" log="protocol: TCP, source: 61.139.105.163, destination: ***, ports: 9000, 3128, 8000, 80, 9090, 8085, 8088, 8090, 9415, 2301, ..." time="Sun Dec 20 23:41:39 2009" username="not logged yet"
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 9415 which use the TCP protocol.
Sat Dec 19 02:56:44 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8080 which use the TCP protocol.
Sat Dec 19 02:56:44 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8085 which use the TCP protocol.
Sat Dec 19 02:56:44 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8088 which use the TCP protocol.
Sat Dec 19 02:56:44 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8089 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 9090 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 6588 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8090 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 1080 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 2301 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 808 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8118 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8888 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 7212 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 1025 which use the TCP protocol.
Sat Dec 19 02:57:14 2009
=>Found attack from 61.139.105.163.
Source port is 12200 and destination port is 8081 which use the TCP protocol.
Your computer's TCP ports:
8080, 9000, 8085, and 6588 have been scanned from 61.139.105.163. -
netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
country: CN
changed: ipadmin@my-public.sc.cninfo.net 20030317
mnt-by: MAINT-CHINANET-SC
source: APNIC
- https://isc.sans.org/ipinfo.html?ip=61.139.105.163
blocked by firewall.
here is the report:
Somebody is scanning your computer.
Your computer's TCP ports:
808, 8118, 8888, and 8081 have been scanned from 61.139.105.163..
Your computer's TCP ports:
6588, 8090, 2301, and 8888 have been scanned from 61.139.105.163.
- netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
- person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
country: CN
changed: ipadmin@my-public.sc.cninfo.net 20030317
mnt-by: MAINT-CHINANET-SC
source: APNIC
- https://isc.sans.org/ipinfo.html?ip=61.139.105.163
Your computer's TCP ports:
6588, 8090, 2301, and 8118 have been scanned from 61.139.105.163 - netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
* https://isc.sans.org/ipinfo.html?ip=61.139.105.163
OrgName: Internet Assigned Numbers Authority
OrgID: IANA
Address: 4676 Admiralty Way, Suite 330
City: Marina del Rey
StateProv: CA
PostalCode: 90292-6695
Country: US
NetRange: 10.0.0.0 - 10.255.255.255
CIDR: 10.0.0.0/8
NetName: RESERVED-10
NetHandle: NET-10-0-0-0-1
Parent:
NetType: IANA Special Use
NameServer: BLACKHOLE-1.IANA.ORG
NameServer: BLACKHOLE-2.IANA.ORG
Comment: This block is reserved for special purposes.
Comment: Please see RFC 1918 for additional information:
Comment: http://www.arin.net/reference/rfc/rfc1918.txt
RegDate:
Updated: 2007-11-27
OrgAbuseHandle: IANA-IP-ARIN
OrgAbuseName: Internet Corporation for Assigned Names and Number
OrgAbusePhone: +1-310-301-5820
OrgAbuseEmail: abuse@iana.org
OrgTechHandle: IANA-IP-ARIN
OrgTechName: Internet Corporation for Assigned Names and Number
OrgTechPhone: +1-310-301-5820
OrgTechEmail: abuse@iana.org
61.139.105.163>>HOP# 20 (final)
OrgName: Asia Pacific Network Information Centre
OrgID: APNIC
Address: PO Box 2131
City: Milton
StateProv: QLD
PostalCode: 4064
Country: AU
ReferralServer: whois://whois.apnic.net
NetRange: 61.0.0.0 - 61.255.255.255
CIDR: 61.0.0.0/8
NetName: APNIC3
NetHandle: NET-61-0-0-0-1
Parent:
NetType: Allocated to APNIC
NameServer: NS1.APNIC.NET
NameServer: NS3.APNIC.NET
NameServer: NS4.APNIC.NET
NameServer: TINNIE.ARIN.NET
NameServer: NS2.LACNIC.NET
NameServer: NS-SEC.RIPE.NET
Comment: This IP address range is not registered in the ARIN database.
Comment: For details, refer to the APNIC Whois Database via
Comment: WHOIS.APNIC.NET or http://wq.apnic.net/apnic-bin/whois.pl
Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
Comment: for the Asia Pacific region. APNIC does not operate networks
Comment: using this IP address range and is not able to investigate
Comment: spam or abuse reports relating to these addresses. For more
Comment: help, refer to http://www.apnic.net/apnic-info/whois_search2/abuse-and-spamming
RegDate: 1997-04-25
Updated: 2009-10-08
OrgTechHandle: AWC12-ARIN
OrgTechName: APNIC Whois Contact
OrgTechPhone: +61 7 3858 3188
OrgTechEmail: search-apnic-not-arin@apnic.net
(UK West Mids.)
Your computer's TCP ports:
2301, 808, 8888, and 8081 have been scanned from 61.139.105.163
netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
https://isc.sans.org/ipinfo.html?ip=61.139.105.163
(61.139.105.163)
Your computer's TCP ports:
8090, 2301, 808, and 8888 have been scanned from 61.139.105.163. -
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
country: CN
- person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
country: CN
changed: ipadmin@my-public.sc.cninfo.net 20030317
mnt-by: MAINT-CHINANET-SC
source: APNIC
Trying to connect on various ports 808, 1025, 3128, 2301, 1080, 6588, 7212, several in the 8000 range, a few in the 9000 range.
% Whois data copyright terms http://www.apnic.net[Who Is Domain][trace][Reverse DNS Search]/db/dbcopyright.html
inetnum: 61.139.105.128[Who Is IP][trace][Reverse IP Search] - 61.139.105.191[Who Is IP][trace][Reverse IP Search]
netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
country: CN
admin-c: XS16-AP
tech-c: XS16-AP
mnt-by: MAINT-CHINANET-SC
changed: [Who Is Domain][trace][Reverse DNS Search] 20010619
status: ASSIGNED NON-PORTABLE
source: APNIC
changed: [Who Is Domain][trace][Reverse DNS Search] 20020827
person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: [Who Is Domain][trace][Reverse DNS Search]
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
country: CN
changed: [Who Is Domain][trace][Reverse DNS Search] 20030317
mnt-by: MAINT-CHINANET-SC
source: APNIC
Your computer's TCP ports:
8000, 8080, 8088, and 9090 have been scanned from 219.153.66.61
Here's the firewall advisory:
Somebody is scanning your computer.
Your computer's TCP ports:
9000, 2301, 8118, and 1080 have been scanned from 61.139.105.163..
Gerard A. Gold
832-858-6797
3-5 times aday he trys to scan my port
All you can do is make sure you have no unsecured services running. Perhaps if enough people complain to their ISP they will blacklist the whole IP address block of 61.139.105.128 - 61.139.105.191
Port scanning from 61.139.105.136. He is scanning me daily! :(
Today and yesterday, these pepole suck, they should be "removed"!
Either it's a bot computer, or some moron. I'm guessing the second one.
when writing this complaint your page shifts to the left and we cannot see the left side of the page until we submit and the page comes back.
It's all too usual an activity from .cn hosts I'm sorry to say.
Somebody is scanning your computer.
Your computer's TCP ports:
8888, 808, 3124, and 11825 have been scanned from 61.139.105.163..
netname: ZIGONG-SCINFO-GOV
descr: Zigong Sciences Informations Academe
descr: ZiGong,Sichuan
descr: PR China
country: CN
admin-c: XS16-AP
tech-c: XS16-AP
mnt-by: MAINT-CHINANET-SC
changed: sxdong@mail.sc.cninfo.net 20010619
status: ASSIGNED NON-PORTABLE
source: APNIC
changed: hm-changed@apnic.net 20020827
person: Xiaodong Shi
nic-hdl: XS16-AP
e-mail: ipadmin@my-public.sc.cninfo.net
address: No.72,Wen Miao Qian Str.
address: Data Communication Bureau Of Sichuan Province
address: Chengdu
address: PR China
phone: +86-28-6190785
fax-no: +86-28-6190641
country: CN
changed: ipadmin@my-public.sc.cninfo.net 20030317
mnt-by: MAINT-CHINANET-SC
source: APNIC
My ISP must be aware of this as their servers would see thousands of requests sent to them daily. I am in the process of waiting on my ISPs explanation as to why they have not blocked this IP from their customers. If it is so widely known about,WHY NO ACTION.. I advise you to do the same and see what lame excuse you get.
Your computer's TCP ports:
7212, 6051, 8888, and 8081 have been scanned from 61.139.105.163..
Somebody is scanning your computer.
Your computer's TCP ports:
1025, 7212, 6051, and 11825 have been scanned from 61.139.105.163..
Anyone any idea how to stop this annoying bugger?
I live in belgium, maybe contact my ISP?
central time u.s. by my firewall.
looks like a very unpopular bastard from the list of complaints.
Your computer's TCP ports:
1080, 8000, 8088, and 8080 have been scanned from 118.168.171.241..
Sat 2009-05-23 19:41:28 TCP flood From 61.139.105.163 port:12200 To ... port:808 droped
Sat 2009-05-23 19:41:30 TCP flood From 61.139.105.163 port:12200 To ... port:3124 droped
Sat 2009-05-23 19:41:31 TCP flood From 61.139.105.163 port:12200 To ... port:3127 droped
Sun 2009-05-24 19:30:39 TCP flood From 61.139.105.163 port:12200 To ... port:808 droped
Sun 2009-05-24 19:32:31 TCP flood From 61.139.105.163 port:12200 To ... port:808 droped
Sun 2009-05-24 19:32:33 TCP flood From 61.139.105.163 port:12200 To ... port:3124 droped
Sun 2009-05-24 19:32:34 TCP flood From 61.139.105.163 port:12200 To ... port:3127 droped
Mon 2009-05-25 16:43:35 TCP flood From 61.139.105.163 port:12200 To ... port:3124 droped
Mon 2009-05-25 16:43:36 TCP flood From 61.139.105.163 port:12200 To ... port:3127 droped
202.97.53.33
202.97.34.58
202.97.24.197
202.97.24.202
?
61.139.105.163
As you see the second to last PC on the traceroute is very likely a firewall.
Scan of 61.139.105.163 (Microsoft Windows Server 2003)
The remote version of Remote Desktop Protocol Server (Terminal
Service) is vulnerable to a man in the middle attack. An attacker may exploit this flaw to decrypt communications betweenmclient and server and obtain sensitive information (passwords, ...).
As you seen on my basic nmap report this guy has alot of filtered services which may be vulnerable. But hay since he has RD running and likely a very simple admin password why not just go for the gusto...
Not shown: 991 closed ports
PORT STATE SERVICE
25/tcp filtered smtp
42/tcp filtered nameserver
135/tcp filtered msrpc
139/tcp filtered netbios-ssn
445/tcp filtered microsoft-ds
593/tcp filtered http-rpc-epmap
1025/tcp open NFS-or-IIS
3389/tcp open ms-term-serv
4444/tcp filtered krb524
I may be posting a Nessus scan soon...
I am like everyone else here, it is being blocked but it sure is bothersome.
61.139.105.163 IP address location & more:
IP address [?]: 61.139.105.163 Copy [Whois] [Reverse IP]
IP country code: CN
IP address country: ip address flag China
IP address state: Sichuan
IP address city: Zigong
IP address latitude: 29.4000
IP address longitude: 104.7833
ISP of this IP [?]: CHINANET Sichuan province network
Organization: Zigong Sciences Informations Academe
Local time in China: 2009-05-23 18:45
Your computer's TCP ports:
6051, 8888, 11825, and 808 have been scanned from 61.139.105.163.and now i scann him retourn,more we can not make!!!
7212, 6051, 8888, and 808 have been scanned from 61.139.105.163..
Your computer\'s TCP ports:
7212, 6051, 8888, and 808 have been scanned from 61.139.105.163..
port 1025, 3127, socks, http, 9000
Gesendet: Montag, 18. Mai 2009 03:43
An: xxx@web.de
Betreff: NETGEAR *Security Alert* [BC:D3:B5]
DNSRight.com
Welcome
Welcome to DNSRight.com Here you will find all your dns and networking tools, for free. Please request a tool or provide some feedback dnsr @ dnsright.com
Lookup here you can scann him retourn !!!!!!!!mfg.to all
DNSRight.com
Welcome
Welcome to DNSRight.com Here you will find all your dns and networking tools, for free. Please request a tool or provide some feedback dnsr @ dnsright.com
Lookup here you can scann him retourn !!!!!!!!mfg.to all
Is anybody working on this to stop them?
No.002 Sun, 2009-04-19 07:29:20 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.003 Sun, 2009-04-19 07:29:21 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.004 Sun, 2009-04-19 07:29:22 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.005 Tue, 2009-05-05 21:12:47 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.006 Tue, 2009-05-05 21:12:48 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.007 Tue, 2009-05-05 21:12:49 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.008 Tue, 2009-05-05 21:12:49 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.009 Wed, 2009-05-06 10:35:28 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN] No.010 Wed, 2009-05-06 10:35:28 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.011 Wed, 2009-05-06 10:35:29 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.012 Wed, 2009-05-06 10:35:29 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.013 Thu, 2009-05-07 01:32:16 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.014 Thu, 2009-05-07 01:32:17 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.015 Thu, 2009-05-07 01:32:17 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.016 Thu, 2009-05-07 01:32:18 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.017 Thu, 2009-05-07 20:01:57 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.018 Thu, 2009-05-07 20:01:58 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
No.019 Thu, 2009-05-07 20:01:58 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN] No.020 Thu, 2009-05-07 20:01:59 - TCP Packet - Source:61.139.105.163 Destination:80.229.***.*** - [Firewall Log-PORT SCAN]
2009-05-01 15:57:31 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-01 15:57:31 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-02 16:32:06 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-02 16:32:07 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-02 16:32:08 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-02 16:32:08 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-03 07:57:25 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-03 07:57:25 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-03 07:57:26 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-03 07:57:27 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-03 13:00:32 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-03 13:00:33 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-03 13:00:33 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-04 05:36:00 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-04 05:36:00 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-04 05:36:02 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-04 05:36:02 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-04 18:50:40 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-04 18:50:40 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-04 18:50:41 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-04 18:50:42 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-05 05:42:42 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-05 05:42:43 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-05 05:42:43 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-05 05:42:44 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-05 22:30:14 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-05 22:30:15 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-05 22:30:15 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-06 11:56:26 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-06 11:56:26 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-06 11:56:27 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-06 11:56:28 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-07 02:49:15 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-07 02:49:16 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-07 02:49:17 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-07 02:49:17 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-07 21:24:09 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-07 21:24:09 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
2009-05-07 21:24:10 - TCP Packet - Source:61.139.105.163 Destination:80.126.xxx.yyy - [Firewall Log-PORT SCAN]
SORRY!
I wonder if it's blind scanning or if something is giving away my online-yness... hmm.
I wonder if it's blind scanning or if something is giving away my online-ness... hmm.
I wonder if it's blind scanning or if something is giving away my online-ness... hmm.
I'd love to see one of those drones over the Pakistan mountains get diverted just once and drill this sob!
Can we overwhelm the email addy associated with the IP address on whois with protests or something?
This guy must be mass scanning huge address ranges. I've changed IP address twice and he's still scanning me.
I/We would not have detected this without our firewalls detecting this, which brings me to wondering, just how many pc's, and in how many countries are these scanning?!? Just by taking a quick look on this page, it is more than 8 countrys world wide! Should we consider this a threat??
I/We would not have detected this without our firewalls detecting this, which brings me to wondering, just how many pc's, and in how many countries are these scanning?!? Just by taking a quick look on this page, it is more than 8 countrys world wide! Should we consider this a threat??
>
> Can you please tell me why my computer is being repeatedly scanned from an IP address registered to you? The details of one set of port scans are below, along with my trace in response.
>
> -----
>
> Subject: NETGEAR *Security Alert* [A8:BE:19]
> Date: Sat,2 May 2009 23:12:21 -0000
> TCP Packet - Source:61.139.105.163 - [PORT SCAN]
> TCP Packet - Source:61.139.105.163 - [PORT SCAN]
>
> -----
>
> Host script results:
> | asn-query:
> | BGP: 61.139.105.0/24 and 61.139.96.0/20 and 61.139.0.0/17 | Country: CN
> |_ Origin AS: 4134 - CHINANET-BACKBONE No.31,Jin-rong Street
> | whois: Record found at whois.apnic.net
> | inetnum: 61.139.105.128 - 61.139.105.191
> | netname: ZIGONG-SCINFO-GOV
> | descr: Zigong Sciences Informations Academe
> | country: CN
> | person: Xiaodong Shi
> |_ email: ipadmin@my-public.sc.cninfo.net
Someone report this ip 61.139.105.163
If you want to get rid of this guy, Try changing your Public IP Address. If you have a router, just go into setup menu and select \"Mac Address\" option and \"Clone Mac Address\". If that fails then just use this simple program called TMAC to change your Mac address!! it worked for me! thanks
If you want to get rid of this guy, Try changing your Public IP Address. If you have a router, just go into setup menu and select "Mac Address" option and "Clone Mac Address". If that fails then just use this simple program called TMAC to change your Mac address!! it worked for me! thanks
6051, 8888, 808, and 8081 have been scanned from 61.139.105.163..
Many more ports scanned as well. Getting really annoyed! Up to 4 scans during 2 minutes.
TCP Packet - Source:61.139.105.163 Destination:81.129.216.6 - [PORT SCAN] TCP Packet - Source:61.139.105.163 Destination:86.133.22.216 - [PORT SCAN]
At this goat it is opened RDP (3389). Similar it is a boat or a virus
Like everyone else I'm getting fed up of who every this is port scanning my firewall multiple times every day
TCP Packet - Source:61.139.105.163 Destination:xxx.xxx.xxx.xxx - [PORT SCAN]
Luckily my firewall blocks it, but hey... make em stop that!
Firewall log:
Fri 2009-04-10 20:04:47 TCP flood From 61.139.105.163 port:12200 To 81.109.###.## port:808 droped
This guy could be a pain!
[INFO] Wed Apr 08 11:03:51 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:3124
[INFO] Wed Apr 08 11:03:49 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8081
[INFO] Wed Apr 08 11:03:48 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8888
[INFO] Wed Apr 08 11:03:46 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:808
[INFO] Wed Apr 08 11:03:45 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:6051
[INFO] Wed Apr 08 11:03:43 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:1025
[INFO] Wed Apr 08 11:03:42 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8089
[INFO] Wed Apr 08 11:03:40 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8118
[INFO] Wed Apr 08 11:03:38 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:7212
[INFO] Wed Apr 08 11:03:37 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:1080
[INFO] Wed Apr 08 11:03:34 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8088
[INFO] Wed Apr 08 11:03:30 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:2301
[INFO] Wed Apr 08 11:03:27 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8000
[INFO] Wed Apr 08 11:03:26 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:80
[INFO] Wed Apr 08 11:03:24 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:3128
[INFO] Wed Apr 08 11:03:23 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8090
[INFO] Wed Apr 08 11:03:21 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:9090
[INFO] Wed Apr 08 11:03:20 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:9000
[INFO] Wed Apr 08 11:03:18 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:6588
[INFO] Wed Apr 08 11:03:16 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8080
[INFO] Wed Apr 08 11:03:51 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:3124
[INFO] Wed Apr 08 11:03:49 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8081
[INFO] Wed Apr 08 11:03:48 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8888
[INFO] Wed Apr 08 11:03:46 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:808
[INFO] Wed Apr 08 11:03:45 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:6051
[INFO] Wed Apr 08 11:03:43 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:1025
[INFO] Wed Apr 08 11:03:42 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8089
[INFO] Wed Apr 08 11:03:40 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8118
[INFO] Wed Apr 08 11:03:38 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:7212
[INFO] Wed Apr 08 11:03:37 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:1080
[INFO] Wed Apr 08 11:03:34 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8088
[INFO] Wed Apr 08 11:03:30 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:2301
[INFO] Wed Apr 08 11:03:27 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8000
[INFO] Wed Apr 08 11:03:26 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:80
[INFO] Wed Apr 08 11:03:24 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:3128
[INFO] Wed Apr 08 11:03:23 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8090
[INFO] Wed Apr 08 11:03:21 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:9090
[INFO] Wed Apr 08 11:03:20 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:9000
[INFO] Wed Apr 08 11:03:18 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:6588
[INFO] Wed Apr 08 11:03:16 2009 Blocked incoming TCP connection request from 61.139.105.163:12200 to 86.3.97.146:8080
Sun, 2009-04-05 00:53:52 - TCP Packet - Source:61.139.105.163 Destination:81.86.248.147 - [PORT SCAN]
Looks like im not the only one..
How can we stop it ?
I have sent an email with details of the IP address to the Chinese Embassy in London demanding an explanation and for the person to be stopped.
Why don't you all do the same in your countries? China will have to stop this activity (it could be the Chinese Government doing the Port Scans and DoS attacks).
8118, 8089, 1025, 6051 und 808
Pain in the A****
61.139.105.163 scan my network every day... I have a secure firewall, but i hate the idiot!!!
Interesting ports on 61.139.105.163:
Not shown: 992 closed ports
PORT STATE SERVICE VERSION
25/tcp filtered smtp
135/tcp filtered msrpc
139/tcp filtered netbios-ssn
445/tcp filtered microsoft-ds
593/tcp filtered http-rpc-epmap
1026/tcp open msrpc Microsoft Windows RPC
3389/tcp open microsoft-rdp Microsoft Terminal Service
4444/tcp filtered krb524
Device type: general purpose
Running (JUST GUESSING) : Microsoft Windows 2003|XP (92%)
Aggressive OS guesses: Microsoft Windows Server 2003 SP1 or SP2 (92%), Microsoft Windows Server 2003 SP1 (88%), Microsoft Windows XP SP2 (86%), Microsoft Windows XP SP2 (Norwegian) (85%), Microsoft Windows Server 2003 Enterprise Edition SP2 (85%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 14 hops
TCP Sequence Prediction: Difficulty=229 (Good luck!)
IP ID Sequence Generation: Randomized
Service Info: OS: Windows
Does anyone know how to stop it? We are really worried about this!
NETGEAR *Security Alert* [FD:BF:7D]
TCP Packet - Source:61.139.105.163 Destination:83.113.187.162 - [PORT SCAN]
TCP Packet - Source:192.168.0.2,1788 Destination:209.85.227.113,80 - [BLOCK]
is scanning port on my firewall twice
or more a day for past 4&5 weeks
waht can be done?????????
gotta check now if intrusion succeeded, cause obviously these guys are pro's. www.ip-adress.com reports that its:
Zigong Sciences Informations Academe.
cheers :/
I checked the logs on my firewall and recognized the the port scans start on 2009/03/09 .. and still scanning the same ports (9090, 8080, 3128, 7212, 1080, 8118, 3124, 6588, 8000).
My IDS also recognized that \"something\" unuasl tried to connect to my host from port 8110 to port 6031. Reason seems to be a trojan \"BACKDOOR fkwp 2.0 runtime\".
Can anybody check his logs and affirm that he has similar detection ..
cheers
I do not really know how my Linux Mandriva 2009.0 works, but here is what happened today:
Just after I turned my computer on, the firewall warned me of someone trying to scan my ports.
I set my firewall on automatic mode (till now, the only way to stop it I could find) and put this IP in a my firewall's black list.
About at the same time, my computer told me there were avaible updatings. I did not update at this moment.
I wanted to check something I suspected yesterday and restarted my computer.
Here is the situation:
-My firewall's automatic mode is set off again.
-The IP has disappeared from the black list.
-When I ask manually for updatings, nothing is found...
From now, I will set the automatic internet connection to "off" till I get some explanations.
Date: 2009-03-22 (15:32 to 15:34)
these portscan attacks have been prevented by software on my computer
i have been on this address for months
just started on the 18th
"Your computer's TCP ports:
8118, 808, 8888, and 1025 have been scanned from 61.139.105.163.."
Stop this idiot
03/17/2009 11:35:55.416 - Possible port scan dropped - Source:61.139.105.163, 12200, WAN - Destination:hi.d.d.en, 6588, WAN - TCP scanned port list, 9090, 9090, 8000, 8000, 7212 -
03/17/2009 11:35:55.416 - Possible port scan dropped - Source:61.139.105.163, 12200, WAN - Destination:hi.d.d.en, 6588, WAN - TCP scanned port list, 9090, 9090, 8000, 8000, 7212 -
03/17/2009 11:35:55.416 - Possible port scan dropped - Source:61.139.105.163, 12200, WAN - Destination:hi.d.d.en, 6588, WAN - TCP scanned port list, 9090, 9090, 8000, 8000, 7212 -
time: 16.00 hours
Situation: The IP adress was blocked by my firewall
The guy scanning my port !!!