Port Details - Port 1026

Jun 30 53 Jul 01 95 Jul 02 50 Jul 03 26 Jul 04 35 Jul 05 51 Jul 06 44 Jul 07 54 Jul 08 50 Jul 09 41 Jul 10 36 Jul 11 41 Jul 12 60 Jul 13 47 Jul 14 48 Jul 15 50 Jul 16 44 Jul 17 41 Jul 18 37 Jul 19 58 Jul 20 58 Jul 21 56 Jul 22 55 Jul 23 52 Jul 24 44 Jul 25 45 Jul 26 43 Jul 27 44 Jul 28 49 Jul 29 36 Jul 30 4 Jun 30 357 Jul 01 151 Jul 02 94 Jul 03 102 Jul 04 50 Jul 05 60 Jul 06 53 Jul 07 63 Jul 08 61 Jul 09 53 Jul 10 88 Jul 11 56 Jul 12 82 Jul 13 75 Jul 14 90 Jul 15 100 Jul 16 69 Jul 17 114 Jul 18 85 Jul 19 64 Jul 20 78 Jul 21 90 Jul 22 91 Jul 23 136 Jul 24 116 Jul 25 57 Jul 26 77 Jul 27 74 Jul 28 78 Jul 29 71 Jul 30 3
[show ascii data]
  • Start Date:
  • End Date:
  • Port:
  • Left Graph:
  • Right Graph:
  • Show Range:Yes No

Port Information

ProtocolServiceName
udpwin-rpcWindows RPC
[get complete service list]

User Comment

Submitted ByDate
Comment
alerter2009-10-04 18:45:22
  The vast majority of these probes on UDP 1026, post-MS-RPC-DCOM exploit ("MS Blaster"), are Windows Messaging Service using alternate ports (UDP 1025-1027) to transmit/blast WMS Desktop Pop-up SPAM. This is because several ISP-s have blocked and/or continue to block UDP 135 post-MS-Blaster. A few offensive and ongoing UDP 1026 WMS SPAMmer source IP-s are: 203.197.199.183 (VSNL-IN), 61.143.182.138 (CHINANET-GD), 200.210.170.10 (LACNIC-ARIN BR), 202.131.221.61 (EAGLE-CN), whose respective ISP-s have been entirely unresponsive and unreactive to ongoing net abuse complaints (check incidents logged with DeepSight Security Analyzer and DShield).
2009-10-04 18:45:22
I wonder if it is related to "new attack vectors for rpc vulnerabilities" http://www2.corest.com/common/showdoc.php?idx=393&;;idxseccion=10
Ken Hollis2004-01-30 19:53:56
UDP Port 1026 (And as AFAIK ports 1027, 1028 and 1029) are the ports for Windows Messenger Popup Spam. See: http://www.lurhq.com/popup_spam.html
Ken Hollis2003-12-23 21:09:04
Greetings and Salutations: Since this is UDP, the spammers forge the source IP address to some unsuspecting party. Do not trust the source address, the packets would have to be traced hop by hop to actually find the perpetrator. Ken
Add a comment

CVE Links

CVE #Description