Last Updated: 2008-06-28 17:24:17 UTC
by Lorna Hutcheson (Version: 1)
One of the things I like to check while on duty are the Trend reports which focus on changes in port activity. While looking at this today, I noticed a sharp increase in both the source and targets for port 19905. Generally target increases don't bother me too much and can be attributed to different things. But with the sources and targets increasing over the past few days for this port, it has me curious. An increase in both sources and targets can be an indicator of an infection of some sort. If you have any ideas for this or any packet captures, please send them our way.