Hi,
Was asked to look at syslog data for a previous client's W2K3 domain as part of a random secuirty audit (doing a favor for a friend). In his syslog I noticed something odd; one of his W2K3 SP1 file servers was intermittantly trying to communicate over ports 139/445 with the IP segment of his DMZ.
Strange thing is that the specific destination IP address does not and has never existed on his DMZ. The packet size varies but is typically around 144 bytes. Even stranger (maybe) is that even though this IP does not exist, packets with a size of 228 bytes are being returned to the file server.
Thinking that this box is in trouble, I've helped him run a number of tests, scans, etc. AV comes up clean (including heuristics and ADS), RootkitRevealer was unremarkable, spyware scanning w/ Windows Defender was unremarkable as well. The connection attempts are not consistent other than when they happen they tend to happen in pairs at 3 hour intervals; first over 139 and then over 445.
I won't pretend to know what's happening with this but if anyone has any ideas....
Thanks - it's always over the holidays...
Was asked to look at syslog data for a previous client's W2K3 domain as part of a random secuirty audit (doing a favor for a friend). In his syslog I noticed something odd; one of his W2K3 SP1 file servers was intermittantly trying to communicate over ports 139/445 with the IP segment of his DMZ.
Strange thing is that the specific destination IP address does not and has never existed on his DMZ. The packet size varies but is typically around 144 bytes. Even stranger (maybe) is that even though this IP does not exist, packets with a size of 228 bytes are being returned to the file server.
Thinking that this box is in trouble, I've helped him run a number of tests, scans, etc. AV comes up clean (including heuristics and ADS), RootkitRevealer was unremarkable, spyware scanning w/ Windows Defender was unremarkable as well. The connection attempts are not consistent other than when they happen they tend to happen in pairs at 3 hour intervals; first over 139 and then over 445.
I won't pretend to know what's happening with this but if anyone has any ideas....
Thanks - it's always over the holidays...