Lsass.exe attack(?) on Port 500

Discussion in 'other security issues & news' started by Tommy, Oct 12, 2006.

Thread Status:
Not open for further replies.
  1. Tommy

    Tommy Registered Member

    Joined:
    Dec 24, 2002
    Posts:
    1,169
    Location:
    Buenos Aires - Munic
    Since about 1 hour somebody is trying to access my PC in a rythm of ten seconds from two different IP's. Never had this. Some ideas? I blocked it, but its getting anoying. :mad:

    2006-10-12 14:01:58
    reject TCP/IP
    receive datagram
    C:\WINDOWS\system32\lsass.exe
    0.0.0.0
    200.161.208.25
    500 500
    PID: 844; Connection: 37

    and

    2006-10-12 14:02:10
    reject TCP/IP
    receive datagram
    C:\WINDOWS\system32\lsass.exe
    0.0.0.0
    201.17.6.14
    500 500
    PID: 844
    Connection: 37

    It is not the isass.exe which is known as a worm.

    Both adresse are listed in the Spam Database.
    http://www.dnsstuff.com/tools/ip4r.ch?ip=200.161.208.25
    and also here:
    http://www.us.sorbs.net/cgi-bin/lookup?NAME=200.161.208.25

    :mad: :mad: Mein Gott das nervt :mad: :mad:
     
    Last edited: Oct 12, 2006
Loading...
Thread Status:
Not open for further replies.