Choose style:

Author Topic: Suspicious outgoing UDP connections using source port 56798  (Read 2073 times)

0 Members and 1 Guest are viewing this topic.

Offline schafdog

  • Backer
  • *
  • Posts: 12
  • Thanks: 0
  • Registered : 10/09/2014
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Suspicious outgoing UDP connections using source port 56798
« on: January 15, 2017, 05:42:08 am »
Using my Almond+ only as a AP behind a firewall.

I see attempts to connect to 75 different IP using this source port. I wonder what this is about. The most active is:

     13 10.0.0.4 195.154.181.4 UDP 56798 48692
     13 10.0.0.4 23.97.59.26 UDP 56798 51173
     13 10.0.0.4 62.76.100.235 UDP 56798 26933
     13 10.0.0.4 62.76.100.235 UDP 56798 50423
     13 10.0.0.4 95.211.191.112 UDP 56798 56789
     14 10.0.0.4 195.154.181.210 UDP 56798 26342
     14 10.0.0.4 37.48.71.87 UDP 56798 52550
     14 10.0.0.4 94.23.18.24 UDP 56798 54495

It cannot be triggered by a incoming request since this port is blocked in the firewall, which I only see from one IP:
62.76.100.235: 2249.netrack.ru.

Do you any documentation on ports use by almond+, so I can block anything else.

 

Page created in 0.105 seconds with 20 queries.