DOS Attacks?!?!?!

Messages
8,474
Location
Australia
Excerp from my router logs:

Thu, 2009-05-21 13:35:37 - TCP Packet - Source:220.253.54.69,41111 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:37 - TCP Packet - Source:220.253.54.69,41112 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:37 - TCP Packet - Source:220.253.54.69,41113 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:37 - TCP Packet - Source:220.253.54.69,41114 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:37 - TCP Packet - Source:220.253.54.69,41115 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:40 - TCP Packet - Source:220.253.54.69,41112 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:40 - TCP Packet - Source:220.253.54.69,41113 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:40 - TCP Packet - Source:220.253.54.69,41126 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:40 - TCP Packet - Source:220.253.54.69,41127 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:40 - TCP Packet - Source:220.253.54.69,41129 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:46 - TCP Packet - Source:220.253.54.69,41115 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:46 - TCP Packet - Source:220.253.54.69,41116 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:46 - TCP Packet - Source:220.253.54.69,41117 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:46 - TCP Packet - Source:220.253.54.69,41110 Destination:220.253.68.193,445 - [DOS] Thu, 2009-05-21 13:35:46 - TCP Packet - Source:220.253.54.69,41130 Destination:220.253.68.193,445 - [DOS]

Now,220.253.68.193 is my IP Adress and i did an I.P Lookup on the other I.P adress and all i could find was:

  • The IP Is from the same ISP as me (netspace)
  • In the Same country as me (Australia)
What is going on?
 
Hardly looks like a DoS attack, you are only getting a few packets per second.

Most likely its someone pinging your comp or maybe port scanning you.
Also may be a Remote Admin Tool server trying to connect to a Trojan on your comp (if there is one).

Its probably just some kid that has found nmap and whipped up a random ip. Dont worry about it.
 
Back
Top Bottom