Port Details - Port 22

Oct 22 797 Oct 24 782 Oct 25 835 Oct 26 1,001 Oct 27 821 Oct 28 896 Oct 29 1,156 Oct 30 1,452 Oct 31 1,271 Nov 01 1,157 Nov 02 1,178 Nov 03 1,478 Nov 04 1,582 Nov 05 1,544 Nov 06 1,281 Nov 07 826 Nov 08 1,310 Nov 09 1,247 Nov 10 1,123 Nov 11 1,063 Nov 12 1,018 Nov 13 1,081 Nov 14 1,000 Nov 15 1,018 Nov 16 999 Nov 17 964 Nov 18 932 Nov 19 948 Nov 20 772 Nov 21 34 Oct 22 96,282 Oct 24 92,660 Oct 25 47,497 Oct 26 97,596 Oct 27 92,109 Oct 28 83,580 Oct 29 98,604 Oct 30 81,844 Oct 31 92,393 Nov 01 97,250 Nov 02 93,218 Nov 03 54,551 Nov 04 41,601 Nov 05 97,930 Nov 06 64,718 Nov 07 24,567 Nov 08 42,480 Nov 09 89,471 Nov 10 103,787 Nov 11 59,865 Nov 12 98,098 Nov 13 56,220 Nov 14 86,541 Nov 15 90,075 Nov 16 31,155 Nov 17 85,277 Nov 18 90,657 Nov 19 89,971 Nov 20 16,902 Nov 21 2,194
[show ascii data]
  • Start Date:
  • End Date:
  • Port:
  • Left Graph:
  • Right Graph:
  • Show Range:Yes No

Port Information

ProtocolServiceName
tcpsshSSH Remote Login Protocol
udpsshSSH Remote Login Protocol
tcpAdoresshd[trojan] Adore sshd
tcpShaft[trojan] Shaft
udppcanywherePCAnywhere (deprecated)
[get complete service list]

User Comment

Submitted ByDate
Comment
2009-10-04 18:45:22
The game Project Torque generate some requests on this port when a race is about to start. It seem to work fine when the request are blocked. At this moment, it is currently in "Closed Beta" state, but shortly it will become "Open Beta". The closed beta started at the begining of august.
pophop2009-10-04 18:45:22
We had an ssh worm pop a box in mid October. Logs showed ssh scanning starting in late September through October. Box had trivial password for exposed service account. Appears that human attackers logged in day after worm and set box up as port 22 scanner. Ran for two days before we caught. Human logins came from Romania. This is what's intersting - we were seeing RST ACKS in ALL our logs globally as if we had been sending SYN packets from all our global IP space to a site in Texas (US). "Ronaldsrecordclub" - 67.15.83.36. Now moved. As if our space was being used in a DOS. Sample: "Deny TCP (no connection) from 67.15.83.36/22 to xxx.xxx.xxx.xxx/3072 flags RST ACK on interface outside" Source port was consistently 3072. Ronaldsrecord google hit talks of its site's "PayPal" enviroment being developed by its "Romanian Development" team. Activity stops in mid-October - about the time SSH worm hit us. I find it odd that we would see this RST ACK activity to port 22 AND have "Romania" associated with both things. Curious if the RST ACK was a DOS or a scan of some sort.
Chris Anderson2007-04-17 02:08:43
I have seen this same attack on a server on my network. A weak password was expoited and a ssh scanner was downloaded from a .ro site. Also included was a list of common usernames and passwords. It appears that it was just checking to see if the password was the same as the username. Once in it starting trying to brute force the root password.
Johannes Ullrich2004-11-10 22:04:01
frequently scanned to look for accounts with weak passwords.
Jason Testart2004-11-09 18:00:01
We've been seeing an extreme amount of SSH scanning at our site over the past week, and just this weekend found a compromised Linux box doing the scanning. My investigation into the compromise found the usual stuff (sniffer, ssh backdoor, irc stuff, etc..) but I found a couple of things particularly interesting: - tools for exploting samba 2.2.x - what looks like a SYN scanner, binary named "ss" with a cover script with command line options for port "22" and a speed setting "6". - a binary named "lol". From what I can tell from the "strings" command and what we've seen, the binary does a dictionary attack to common accounts such as "root" and "test" using SSH. The tools used were downloaded from sites in the .ro domain (Romania?).
Add a comment

CVE Links

CVE #Description
CVE-2001-144 "CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow."
CVE-2002-390 "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized