Loading...
[get complete service list]
Port Information
Protocol Service Name
tcp --- ---
Top IPs Scanning
Today Yesterday
208.87.243.205 (5)208.87.243.205 (4)
92.118.39.18 (3)152.32.208.169 (4)
194.180.49.42 (2)83.222.191.170 (2)
79.124.62.230 (2)89.248.163.226 (2)
118.193.39.117 (2)45.125.236.108 (2)
193.163.125.94 (1)101.36.127.85 (2)
193.163.125.133 (1)193.163.125.49 (2)
118.194.251.144 (1)193.163.125.175 (2)
193.163.125.243 (1)165.154.135.215 (2)
193.163.125.7 (1)193.163.125.107 (2)
Port diary mentions
URL
Happy Valentine's Day; ARCserve probes?; OWA issue; new Opera version
Port 41523; Linux Exploit; Phishing Name server; New Feature: tcp %; ssh attacks; MSRC blog
New mydoom variant; ARCserve exploitation has begun... got Port 41523 TCP packets?
User Comments
Submitted By Date
Comment
Joy Whitney 2005-03-10 08:09:02
This is the Computer Associates Brightstor Arcserver discovery service port. All of the machines in one address range on our WAN was hit at about 8:20PST on 2/24/05. On most machines it just killed the process. On 5 machines it killed the process but also attempted to write a file named wumgrs32.exe. Also found a file named o (with the same time stamp)which was an ftp script to download the mentioned exe file.
CVE Links
CVE # Description