Port Details - Port 1026

Oct 22 60 Oct 24 49 Oct 25 127 Oct 26 134 Oct 27 81 Oct 28 164 Oct 29 93 Oct 30 56 Oct 31 37 Nov 01 87 Nov 02 106 Nov 03 64 Nov 04 57 Nov 05 61 Nov 06 60 Nov 07 56 Nov 08 56 Nov 09 58 Nov 10 52 Nov 11 54 Nov 12 56 Nov 13 48 Nov 14 51 Nov 15 51 Nov 16 63 Nov 17 86 Nov 18 73 Nov 19 96 Nov 20 121 Nov 21 17 Oct 22 419 Oct 24 664 Oct 25 936 Oct 26 1,275 Oct 27 903 Oct 28 602 Oct 29 1,278 Oct 30 572 Oct 31 515 Nov 01 822 Nov 02 490 Nov 03 629 Nov 04 1,068 Nov 05 424 Nov 06 633 Nov 07 778 Nov 08 528 Nov 09 1,471 Nov 10 786 Nov 11 241 Nov 12 332 Nov 13 693 Nov 14 738 Nov 15 222 Nov 16 298 Nov 17 358 Nov 18 212 Nov 19 265 Nov 20 217 Nov 21 40
[show ascii data]
  • Start Date:
  • End Date:
  • Port:
  • Left Graph:
  • Right Graph:
  • Show Range:Yes No

Port Information

ProtocolServiceName
udpwin-rpcWindows RPC
[get complete service list]

User Comment

Submitted ByDate
Comment
alerter2009-10-04 18:45:22
  The vast majority of these probes on UDP 1026, post-MS-RPC-DCOM exploit ("MS Blaster"), are Windows Messaging Service using alternate ports (UDP 1025-1027) to transmit/blast WMS Desktop Pop-up SPAM. This is because several ISP-s have blocked and/or continue to block UDP 135 post-MS-Blaster. A few offensive and ongoing UDP 1026 WMS SPAMmer source IP-s are: 203.197.199.183 (VSNL-IN), 61.143.182.138 (CHINANET-GD), 200.210.170.10 (LACNIC-ARIN BR), 202.131.221.61 (EAGLE-CN), whose respective ISP-s have been entirely unresponsive and unreactive to ongoing net abuse complaints (check incidents logged with DeepSight Security Analyzer and DShield).
2009-10-04 18:45:22
I wonder if it is related to "new attack vectors for rpc vulnerabilities" http://www2.corest.com/common/showdoc.php?idx=393&;;idxseccion=10
Ken Hollis2004-01-30 19:53:56
UDP Port 1026 (And as AFAIK ports 1027, 1028 and 1029) are the ports for Windows Messenger Popup Spam. See: http://www.lurhq.com/popup_spam.html
Ken Hollis2003-12-23 21:09:04
Greetings and Salutations: Since this is UDP, the spammers forge the source IP address to some unsuspecting party. Do not trust the source address, the packets would have to be traced hop by hop to actually find the perpetrator. Ken
Add a comment

CVE Links

CVE #Description