You are not logged in.
Pages: 1
Does anyone have any idea what UDP port 18273 is? I'm seeing an unusually large amount of blocks on my firewall for this. I find it strange for several reasons:
1) It's UDP 18273.
2) There's over 2000 blocks for it already this week.
3) It's from all over the world, not just one source.
Just this week:
3 SRC=109.110.83.26
3 SRC=109.89.12.169
3 SRC=156.26.118.151
3 SRC=193.136.129.191
174 SRC=213.88.78.9
66 SRC=2.36.48.163
3 SRC=41.121.28.166
117 SRC=78.134.48.165
218 SRC=79.16.16.15
18 SRC=79.25.116.103
9 SRC=79.27.13.120
3 SRC=79.55.85.213
3 SRC=80.181.72.49
188 SRC=80.68.181.94
3 SRC=80.86.125.14
3 SRC=81.165.118.247
166 SRC=82.56.62.209
34 SRC=83.211.66.28
9 SRC=85.230.4.24
337 SRC=87.1.123.171
99 SRC=87.1.231.85
299 SRC=87.19.62.228
3 SRC=87.4.233.216
33 SRC=87.8.95.129
11 SRC=93.145.209.241
202 SRC=93.146.150.147I've got a traffic capture running now to try and see what's going on, just wondering if anyone else is seeing anything similar.
Are you familiar with our Forum Rules, and How To Ask Questions The Smart Way?
BlueHackers // fscanary // resticctl
Offline
Capture if anyone wants a closer look... Nothing stands out as an explanation:
http://ompldr.org/vNnJ5Zw/udp18273.pcap
Are you familiar with our Forum Rules, and How To Ask Questions The Smart Way?
BlueHackers // fscanary // resticctl
Offline
huh. no clue.
Are all the source ports the same too? In the pcap they were.
From those caps, it is hard to tell if it was response packets from outbound connection attempts that NAT rules had simply expired on, or inbound traffic.
src: 7513/udp
dst: 18273/udp
iana port allocations list says:
# 7512-7541 Unassigned
# 18263-18462 Unassigned
If you do reverse lookups on those IP addresses, you get..
59.167.180.125 - mail.naturesorganics.com.au -- apnic ip block owner -- http://whois.arin.net/rest/nets;q=59.16 … ARIN=false
87.4.233.216 - host216-233-dynamic.4-87-r.retail.telecomitalia.it. -- ripe ip block owner info -- http://www.db.ripe.net/whois?form_type= … rch=Search
So you have one ip that is a mailserver (in what appears to be melborne AU) and one that is some isp end user (in italy. Udine?).
I guess it depends on which IP is yours. ![]()
If you run the mailserver, I would suggest you look for anything bound to unexpected ports, and maybe do a rootkit check run or something. If nothing untorward shows up, just keep an eye on the logs looking for anything else unusual.
"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍
Offline
The 59. address is ours. It's a CentOS box acting as a primary firewall. There's an additional /29 behind the firewall, but all outbound is SNAT'ed to the 59. address above. Nothing seems untoward outbound as best I can tell. I'll have to have another look tomorrow.
That's just one example of an inbound connection attempt that I grabbed this morning after reviewing the daily logs.
We've been having a discussion on the SANS group about it, but no conclusion made:
http://groups.google.com/group/iscdshie … 941d092764
Are you familiar with our Forum Rules, and How To Ask Questions The Smart Way?
BlueHackers // fscanary // resticctl
Offline
Yeah. hmm.
I guess I would try a capture on the egress FW box with src= 18273/udp just to see if this is return data from some outbound naughty service (pwned box or control box for some botnet), or if it is indeed all inbound connection attempts.
keep us (me) posted though. very interesting.
"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍
Offline
I guess I would try a capture on the egress FW box with src= 18273/udp just to see if this is return data from some outbound naughty service (pwned box or control box for some botnet), or if it is indeed all inbound connection attempts.
Nothing on that port... Trying to get a pcap of all traffic to/from a specific host to see what (if any) other ports are talking to it. I think I might be chasing my tail though ![]()
Will let you know if I find anything ![]()
(OT: NYE Tacos tonight
)
Are you familiar with our Forum Rules, and How To Ask Questions The Smart Way?
BlueHackers // fscanary // resticctl
Offline
wooo tacos!![]()
"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍
Offline
Pages: 1