Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: Port 443 (tcp/udp) Attack Activity - SANS Internet Storm Center Port 443 (tcp/udp) Attack Activity


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Loading...
[get complete service list]
Port Information
Protocol Service Name
tcp https HTTP protocol over TLS SSL
udp https HTTP protocol over TLS/SSL
TCP [ICS] OPC UA XML [ICS] OPC UA XML
Top IPs Scanning
TodayYesterday
5.9.28.205 (6639)5.9.28.205 (44749)
74.50.61.103 (2361)74.50.61.103 (14213)
138.99.216.228 (638)97.85.120.211 (3304)
97.85.120.211 (563)138.99.216.228 (2710)
183.136.225.35 (498)183.136.225.35 (2044)
185.7.214.104 (497)45.95.147.25 (1896)
185.189.182.234 (379)78.128.113.170 (1836)
45.79.130.8 (267)18.170.239.155 (1004)
193.106.29.122 (213)185.7.214.104 (942)
212.102.58.164 (189)74.76.32.107 (934)
Port diary mentions
URL
LSASS exploit, SSL PCT exploits, port 559 (tcp) proxy hunter, Bagle.Z
Increased SSL Activity; Exploits for MS04-022; Mailbag
Quiet Day;TCP443; Firefox GIF image handling heap overflow exploit; MS javaprxy.dll update
port 443 https increase
User Comments
Submitted By Date
Comment
Sunny Dhbahai 2013-03-05 13:43:50
Redis Server Port which client can run queries. Default Port Exposed to Internet Could Face Brute Force Attacks. Nmap Brute Force Script For Radis: http://nmap.org/nsedoc/scripts/redis-brute.html
Alexander Dupuy 2010-11-23 14:17:15
UDP/443 is typically Skype traffic. From http://download.skype.com/share/business/guides/skype-it-administrators-guide.pdf (p.10 section 2.1.2 Operations): "It also uses UDP 443 to test network connectivity." These network probes typically have 18 byte payloads from the client (dst port UDP/443) and 26 byte payloads from the server (src port UDP/443)
Add a comment
CVE Links
CVE # Description
CVE-2014-0160
CVE-2014-0224
CVE-2014-6321
CVE-2016-8610