Last update: 2020-09-19

AS29073 Quasi Networks LTD.
Reported breaches

  • Port scan
The publicly-available Whois record found at whois.ripe.net server.

% This is the RIPE Database query service.
% The objects are in RPSL format.
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
%       To receive output for a database update, use the "-B" flag.

% Information related to ' -'

% Abuse contact for ' -' is '[email protected]'

inetnum: -
netname:        NET-4-49
descr:          IPV NETBLOCK
country:        NL
geoloc:         52.370216 4.895168
org:            ORG-IVI1-RIPE
admin-c:        IVI24-RIPE
tech-c:         IVI24-RIPE
status:         ASSIGNED PA
mnt-by:         IPV
mnt-lower:      IPV
mnt-routes:     IPV
created:        2019-02-04T13:24:48Z
last-modified:  2019-02-04T13:24:48Z
source:         RIPE

% Information related to ''

origin:         AS202425
remarks:        +-----------------------------------------------
remarks:        | For abuse e-mail [email protected]
remarks:        | We do not always reply to abuse.
remarks:        | But we do take care your report is dealt with!
remarks:        +-----------------------------------------------
mnt-by:         IPV
created:        2019-02-08T16:09:44Z
last-modified:  2019-02-08T16:09:44Z
source:         RIPE

% This query was served by the RIPE Database Query Service version 1.97.2 (BLAARKOP)

12 security incident(s) reported by users

BHD Honeypot
Port scan

In the last 24h, the attacker ( attempted to scan 23 ports.
The following ports have been scanned: 6131/tcp, 6260/tcp, 6125/tcp, 6106/tcp (MPS Server), 6275/tcp, 6290/tcp, 6300/tcp (BMC GRX), 6292/tcp, 6181/tcp, 6194/tcp, 6128/tcp, 6278/tcp, 6118/tcp, 6299/tcp, 6107/tcp (ETC Control), 6101/tcp (SynchroNet-rtc), 6121/tcp (SPDY for a faster web), 6115/tcp (Xic IPC Service), 6285/tcp, 6170/tcp, 6297/tcp, 6273/tcp, 6105/tcp (Prima Server).
BHD Honeypot
Port scan

In the last 24h, the attacker ( attempted to scan 27 ports.
The following ports have been scanned: 6106/tcp (MPS Server), 6289/tcp, 6103/tcp (RETS), 6300/tcp (BMC GRX), 6181/tcp, 6194/tcp, 6154/tcp, 6296/tcp, 6284/tcp, 6298/tcp, 6235/tcp, 6123/tcp (Backup Express), 6114/tcp (WRspice IPC Service), 6293/tcp, 6120/tcp, 6102/tcp (SynchroNet-upd), 6147/tcp (Montage License Manager), 6299/tcp, 6107/tcp (ETC Control), 6288/tcp, 6101/tcp (SynchroNet-rtc), 6258/tcp, 6297/tcp, 6183/tcp, 6295/tcp, 6116/tcp (XicTools License Manager Service), 6105/tcp (Prima Server).
BHD Honeypot
Port scan

In the last 24h, the attacker ( attempted to scan 22 ports.
The following ports have been scanned: 5495/tcp, 5305/tcp (HA Cluster Test), 5321/tcp (Webservices-based Zn interface of BSF over SSL), 5306/tcp (Sun MC Group), 5376/tcp, 5301/tcp (HA cluster general services), 5427/tcp (SCO-PEER-TTA), 5454/tcp (APC 5454), 5308/tcp (CFengine), 5307/tcp (SCO AIP), 5498/tcp, 5302/tcp (HA cluster configuration), 5496/tcp, 5487/tcp, 5494/tcp, 5401/tcp (Excerpt Search Secure), 5483/tcp, 5303/tcp (HA cluster probing), 5310/tcp (Outlaws), 5500/tcp (fcp-addr-srvr1), 5486/tcp, 5499/tcp.
BHD Honeypot
Port scan

In the last 24h, the attacker ( attempted to scan 32 ports.
The following ports have been scanned: 4703/tcp (Network Performance Quality Evaluation System Test Service), 4889/tcp, 4874/tcp, 4702/tcp (NetXMS Server Synchronization), 4846/tcp (Contamac ICM Service), 4711/tcp, 4884/tcp (HiveStor Distributed File System), 4708/tcp, 4715/tcp, 4731/tcp (Remote Capture Protocol), 4784/tcp (BFD Multihop Control), 4869/tcp (Photon Relay Debug), 4723/tcp, 4896/tcp, 4709/tcp, 4894/tcp (LysKOM Protocol A), 4757/tcp, 4886/tcp, 4877/tcp, 4898/tcp, 4722/tcp, 4754/tcp, 4900/tcp (HyperFileSQL Client/Server Database Engine), 4701/tcp (NetXMS Management), 4704/tcp (Assuria Insider), 4868/tcp (Photon Relay), 4887/tcp, 4718/tcp, 4899/tcp (RAdmin Port), 4761/tcp, 4811/tcp.
Port scan blocked
Port scan

A port scan was detected and blocked.
Remote IP:
BHD Honeypot
Port scan

Port scan from IP: detected by psad.
BHD Honeypot
Port scan

In the last 24h, the attacker ( attempted to scan 29 ports.
The following ports have been scanned: 3670/tcp (SMILE TCP/UDP Interface), 3685/tcp (DS Expert Agent), 3651/tcp (XRPC Registry), 3678/tcp (DataGuardianLT), 3556/tcp (Sky Transport Protocol), 3700/tcp (LRS NetPage), 3688/tcp (simple-push Secure), 3697/tcp (NavisWorks License System), 3686/tcp (Trivial Network Management), 3540/tcp (PNRP User Port), 3503/tcp (MPLS LSP-echo Port), 3565/tcp (M2PA), 3511/tcp (WebMail/2), 3641/tcp (Netplay Port 2), 3535/tcp (MS-LA), 3532/tcp (Raven Remote Management Control), 3671/tcp (e Field Control (EIBnet)), 3516/tcp (Smartcard Port), 3519/tcp (Netvion Messenger Port), 3571/tcp (MegaRAID Server Port), 3513/tcp (Adaptec Remote Protocol), 3683/tcp (BMC EDV/EA), 3642/tcp (Juxml Replication port), 3509/tcp (Virtual Token SSL Port), 3695/tcp (BMC Data Collection), 3501/tcp (iSoft-P2P), 3558/tcp (MCP user port), 3692/tcp (Brimstone IntelSync), 3504/tcp (IronStorm game server).
BHD Honeypot
Port scan

In the last 24h, the attacker ( attempted to scan 22 ports.
The following ports have been scanned: 2303/tcp (Proxy Gateway), 2346/tcp (Game Connection Port), 2485/tcp (Net Objects1), 2302/tcp (Bindery Support), 2489/tcp (TSILB), 2321/tcp (RDLAP), 2493/tcp (Talarian MQS), 2356/tcp (GXT License Managemant), 2461/tcp (qadmifoper), 2307/tcp (pehelp), 2472/tcp (C3), 2336/tcp (Apple UG Control), 2349/tcp (Diagnostics Port), 2470/tcp (taskman port), 2455/tcp (WAGO-IO-SYSTEM), 2323/tcp (3d-nfsd), 2500/tcp (Resource Tracking system server), 2301/tcp (Compaq HTTP), 2353/tcp (pspserver), 2311/tcp (Message Service), 2499/tcp (UniControl), 2478/tcp (SecurSight Authentication Server (SSL)).
BHD Honeypot
Port scan

Port scan from IP: detected by psad.
BHD Honeypot
Port scan

In the last 24h, the attacker ( attempted to scan 30 ports.
The following ports have been scanned: 758/tcp (nlogin), 761/tcp (rxe), 714/tcp (IRIS over XPCS), 708/tcp, 703/tcp, 707/tcp (Borland DSJ), 878/tcp, 887/tcp (ICL coNETion server info), 900/tcp (OMG Initial Refs), 876/tcp, 895/tcp, 886/tcp (ICL coNETion locate server), 888/tcp (CD Database Protocol), 891/tcp, 723/tcp, 728/tcp, 715/tcp (IRIS-LWZ), 890/tcp, 701/tcp (Link Management Protocol (LMP)), 713/tcp (IRIS over XPC), 896/tcp, 894/tcp, 705/tcp (AgentX), 899/tcp, 719/tcp, 898/tcp, 702/tcp (IRIS over BEEP), 720/tcp, 897/tcp.
BHD Honeypot
Port scan

In the last 24h, the attacker ( attempted to scan 17 ports.
The following ports have been scanned: 206/tcp (AppleTalk Zone Information), 293/tcp, 265/tcp (X-Bone CTL), 291/tcp, 270/tcp, 210/tcp (ANSI Z39.50), 285/tcp, 300/tcp, 202/tcp (AppleTalk Name Binding), 204/tcp (AppleTalk Echo), 201/tcp (AppleTalk Routing Maintenance), 292/tcp, 274/tcp, 297/tcp, 219/tcp (Unisys ARPs), 216/tcp (Computer Associates Int'l License Server), 275/tcp.
BHD Honeypot
Port scan

Port scan from IP: detected by psad.


