Lsass.exe attack(?) on Port 500

Discussion in 'other security issues & news' started by Tommy, Oct 12, 2006.

Thread Status:
Not open for further replies.
  1. Tommy

    Tommy Registered Member

    Joined:
    Dec 24, 2002
    Posts:
    1,169
    Location:
    Buenos Aires - Munic
    Since about 1 hour somebody is trying to access my PC in a rythm of ten seconds from two different IP's. Never had this. Some ideas? I blocked it, but its getting anoying. :mad:

    2006-10-12 14:01:58
    reject TCP/IP
    receive datagram
    C:\WINDOWS\system32\lsass.exe
    0.0.0.0
    200.161.208.25
    500 500
    PID: 844; Connection: 37

    and

    2006-10-12 14:02:10
    reject TCP/IP
    receive datagram
    C:\WINDOWS\system32\lsass.exe
    0.0.0.0
    201.17.6.14
    500 500
    PID: 844
    Connection: 37

    It is not the isass.exe which is known as a worm.

    Both adresse are listed in the Spam Database.
    http://www.dnsstuff.com/tools/ip4r.ch?ip=200.161.208.25
    and also here:
    http://www.us.sorbs.net/cgi-bin/lookup?NAME=200.161.208.25

    :mad: :mad: Mein Gott das nervt :mad: :mad:
     
    Last edited: Oct 12, 2006
Loading...
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.