[Dshield] Dst. ports 33438, 33437

Johannes B. Ullrich jullrich at euclidian.com
Thu Aug 11 11:18:46 GMT 2005

Fergie (Paul Ferguson) wrote:
> ...and, now I see an adjacent port as well:
> 2005-08-10 21:21:48 -05:00	87744681	1	14484	67.64.90.x	33436	udp

All points to Unix traceroute. Nothing particular "malicious".

> --> fcp-2.chg.pnap.net

pnap (aka Internap) is in the route-optimization business. They
ping/traceroute various random hosts to check for the best route to
given ISPs/Networks.

See: http://www.internap.com/

In some cases, you trigger these services by visiting a web site using
them. In other cases its just them trying to figure out the internet
topology in general.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 256 bytes
Desc: OpenPGP digital signature
Url : http://www.dshield.org/pipermail/list/attachments/20050811/17300ef8/signature.bin

More information about the list mailing list