I need some objective minds in a little scenario. Ok this actually happened but I like to know what do you think when you see this on your router A quick Google of the Ip gimme the following IP address information: http://www.magic-net.info/blacklist_lookup/188.8.131.52 Blacklist lookup January 14 2011.html Complaint lodged for 184.108.40.206 are a lot of people complaining bout the same ip port scanning. I assume its picked up by their routers firewall. Heres the list http://www.liveipmap.com/220.127.116.11 Complaint lodged for 18.104.22.168 Dated back from 7 months ago to couple of weeks. Then I came across this thread of another user picking up the following http://forums.majorgeeks.com/showthread.php?t=229454 Luckily Avira notified him and he had it checked out. The thread was also bout 8 months ago. Further one the following was found on his pc Now is it a stupid hacker using the same old ip for months on end or does that IP look like something part of a botnet or would you dismiss it as a plain and normal port scan?