[Snort-sigs] UDP on port 6667

JJC cummingsj at ...2420...
Thu Mar 7 10:00:10 EST 2013


Without seeing the traffic it's tough to say.. now, having said that..
that it's fairly suspect behaviour and I would want to inspect those
packets if I were you.

JJC

On Thu, Mar 7, 2013 at 7:57 AM, Aisling Brennan
<aislingbrennan21 at ...2420...> wrote:
> Hi
>
> I'm observing some unusual behaviour from our servers, attempting to access
> external devices on port 6667.
>
> Is this known malware?
>
> Aisling
>
> ------------------------------------------------------------------------------
> Symantec Endpoint Protection 12 positioned as A LEADER in The Forrester
> Wave(TM): Endpoint Security, Q1 2013 and "remains a good choice" in the
> endpoint security space. For insight on selecting the right partner to
> tackle endpoint security challenges, access the full report.
> http://p.sf.net/sfu/symantec-dev2dev
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-sigs
> http://www.snort.org
>
>
> Please visit http://blog.snort.org for the latest news about Snort!




More information about the Snort-sigs mailing list