[nsp-sec] 1640/tcp puzzle.

Scott A. McIntyre scott at xs4all.net
Mon Jun 30 01:44:03 EDT 2008


Hi teams,

A few weeks ago a handful of my customers started spewing packets to  
one particular IP address on port 1640/tcp.  This lit up my darknet,  
but the problem went away.  However, it's returned with a vengeance.   
The destination is always 100.100.100.200:1640 and the src host count  
has skyrocketed (from 1 or 2 per day to over 100).  Does this  
combination trigger anything in anyone's mind?

My default answer of "probably something p2p related" seems likely,  
but if someone else has thoughts I'd appreciate it!

Cheers,

Scott A. McIntyre
XS4ALL Internet B.V.






More information about the nsp-security mailing list