Reported Spike in tcp/5901 and tcp/5900
We have had a report of elevated activity on tcp/5901 and 5900, anyone else observing a significant spike in VNC scans?
Richard Porter
--- ISC Handler on Duty
Keywords: Scan Activity VNC
5 comment(s)
×
Diary Archives
Comments
Zach W.
Anonymous
Oct 12th 2013
1 decade ago
ASN Continent Country
4621 Asia TH
17090 North America US
50613 Europe IS
20454 North America US
42708 Europe SE
25761 North America US
7922 North America US
4134 Asia CN
9848 Asia KR
50613 Europe DE
32475 North America US
30217 North America US
19994 North America US
9931 Asia TH
39743 Europe RO
16265 Europe NL
36493 North America CA
15699 Europe ES
21844 North America US
13768 North America US
17621 Asia CN
4837 Asia CN
8972 Europe DE
18239 Asia CN
10036 Asia KR
9381 Asia HK
30633 North America US
Any chance you can post that script and details on the vulnerability it may have used to execute? Perhaps poor VNC credentials?
Anonymous
Oct 12th 2013
1 decade ago
185.6.80.195
192.241.137.210
203.174.53.92
216.213.84.131
223.252.19.35
59.51.66.175
74.205.222.27
Anonymous
Oct 12th 2013
1 decade ago
Almost all the IP's are registered to South American countries, many IP's LACNIC have reclaimed and have not been re-allocated yet. I would guess that someone at LACNIC are borrowing IP's for abusive purposes.
Anonymous
Oct 13th 2013
1 decade ago
Anonymous
Oct 13th 2013
1 decade ago