[Snort-users] [Intrusions] Strange ICMP
rshuck at ...6736...
Tue May 18 08:44:08 EDT 2004
I am detecting an increased amount of ICMP Ping traffic. The strange
thing is that there are several sources that are hitting us about 1000
times a week. All of these sources have a last octet of some form of 36
188.8.131.52 & 37
184.108.40.206 & 37
220.127.116.11 & 37
18.104.22.168 & 237
22.214.171.124 & 137
These are from different ISPs and in a couple countries. The destination
is on a Cable Modem that has no inbound access. It's not causing an
issue, it's just anomalous.
Anyone else seeing this kind of traffic, or have any ideas on the
Ron Shuck, CISSP, GCIA, CCSE - Managing Consultant
Buchanan Associates - A Technology Company in the People Business
Intrusions mailing list
Intrusions at ...11822...
More information about the Snort-users