This is an automated message from Columbia University IT Security. You are
receiving it because you are listed as the abuse contact in WHOIS for the machine
referred to below. This machine either attempted to gain unauthorized
access to one or more machines, or was scanning the network at Columbia
University.
It is possible that this alert is the result of a reflection attack against your network with a spoofed origin matching Columbia University’s network.
Details are provided below. Please take all necessary
steps to mitigate such attacks, or ignore this notice if this traffic is spoofed.
If you have received this message in error, or if this incident
reported is inappropriate, please contact
security@columbia.edu so that we can update our procedures. Please include the entire
body of this message.
Thank You.
Columbia University IT Security
security@columbia.edu Name: static.57.77.181.135.clients.your-server.de
Address: 135.181.77.57
Incident type: 3389/tcp
First attempt: 17-dec-2020 18:55:00 GMT-0500
Last attempt: 17-dec-2020 18:55:00 GMT-0500
Total attempts: 411
17-Dec-2020 18:53:12 GMT-
0500 135.181.77.57:4541 -> 128.59.150.55:
3389 6 1123 17-Dec-2020 18:53:12 GMT-
0500 135.181.77.57:3512 -> 128.59.154.255:
3389 6 374 17-Dec-2020 18:53:12 GMT-
0500 135.181.77.57:4762 -> 128.59.65.213:
3389 6 328 17-Dec-2020 18:53:12 GMT-
0500 135.181.77.57:5763 -> 128.59.207.63:
3389 6 2761 17-Dec-2020 18:53:12 GMT-
0500 135.181.77.57:5772 -> 128.59.246.143:
3389 6 2647 17-Dec-2020 18:53:12 GMT-
0500 135.181.77.57:3723 -> 128.59.246.143:
3389 6 374 17-Dec-2020 18:53:13 GMT-
0500 135.181.77.57:6215 -> 128.59.178.95:
3389 6 1683 17-Dec-2020 18:53:13 GMT-
0500 135.181.77.57:6402 -> 128.59.29.175:
3389 6 1784 17-Dec-2020 18:53:13 GMT-
0500 135.181.77.57:6537 -> 128.59.150.55:
3389 6 2647 17-Dec-2020 18:53:13 GMT-
0500 135.181.77.57:6404 -> 128.59.65.213:
3389 6 1878 17-Dec-2020 18:53:15 GMT-
0500 135.181.77.57:9397 -> 128.59.65.213:
3389 6 1946 17-Dec-2020 18:53:16 GMT-
0500 135.181.77.57:9998 -> 128.59.246.143:
3389 6 1534 17-Dec-2020 18:53:16 GMT-
0500 135.181.77.57:10159 -> 128.59.154.100:
3389 6 1657 17-Dec-2020 18:53:16 GMT-
0500 135.181.77.57:10767 -> 128.59.239.35:
3389 6 2729 17-Dec-2020 18:53:19 GMT-
0500 135.181.77.57:14391 -> 128.59.65.213:
3389 6 1894 17-Dec-2020 18:53:19 GMT-
0500 135.181.77.57:14705 -> 128.59.29.175:
3389 6 1824 17-Dec-2020 18:53:19 GMT-
0500 135.181.77.57:14797 -> 128.59.178.95:
3389 6 1868 17-Dec-2020 18:53:20 GMT-
0500 135.181.77.57:14984 -> 128.59.207.63:
3389 6 2381 17-Dec-2020 18:53:20 GMT-
0500 135.181.77.57:14922 -> 128.59.239.35:
3389 6 2349 17-Dec-2020 18:53:20 GMT-
0500 135.181.77.57:14875 -> 128.59.150.55:
3389 6 2045 17-Dec-2020 18:53:20 GMT-
0500 135.181.77.57:15162 -> 128.59.65.213:
3389 6 1761 17-Dec-2020 18:53:20 GMT-
0500 135.181.77.57:15837 -> 128.59.154.255:
3389 6 2695 17-Dec-2020 18:53:21 GMT-
0500 135.181.77.57:16241 -> 128.59.154.100:
3389 6 1410 17-Dec-2020 18:53:24 GMT-
0500 135.181.77.57:20386 -> 128.59.246.143:
3389 6 2595 17-Dec-2020 18:53:24 GMT-
0500 135.181.77.57:20334 -> 128.59.154.100:
3389 6 1651 17-Dec-2020 18:53:24 GMT-
0500 135.181.77.57:21108 -> 128.59.65.213:
3389 6 1900 17-Dec-2020 18:53:24 GMT-
0500 135.181.77.57:21140 -> 128.59.150.55:
3389 6 1914 17-Dec-2020 18:53:25 GMT-
0500 135.181.77.57:21258 -> 128.59.207.63:
3389 6 2159 17-Dec-2020 18:53:28 GMT-
0500 135.181.77.57:25533 -> 128.59.239.35:
3389 6 2697 17-Dec-2020 18:53:28 GMT-
0500 135.181.77.57:25080 -> 128.59.29.175:
3389 6 1444 17-Dec-2020 18:53:28 GMT-
0500 135.181.77.57:25274 -> 128.59.180.83:
3389 6 1671 17-Dec-2020 18:53:28 GMT-
0500 135.181.77.57:25694 -> 128.59.65.213:
3389 6 2033 17-Dec-2020 18:53:29 GMT-
0500 135.181.77.57:26737 -> 128.59.246.143:
3389 6 2647 17-Dec-2020 18:53:29 GMT-
0500 135.181.77.57:26560 -> 128.59.154.100:
3389 6 1657 17-Dec-2020 18:53:29 GMT-
0500 135.181.77.57:27165 -> 128.59.29.175:
3389 6 1876 17-Dec-2020 18:53:29 GMT-
0500 135.181.77.57:27242 -> 128.59.150.55:
3389 6 1898 17-Dec-2020 18:53:32 GMT-
0500 135.181.77.57:30853 -> 128.59.180.83:
3389 6 1862 17-Dec-2020 18:53:33 GMT-
0500 135.181.77.57:31436 -> 128.59.29.175:
3389 6 1090 17-Dec-2020 18:53:33 GMT-
0500 135.181.77.57:32408 -> 128.59.207.63:
3389 6 2761 17-Dec-2020 18:53:34 GMT-
0500 135.181.77.57:32748 -> 128.59.154.100:
3389 6 1050 17-Dec-2020 18:53:37 GMT-
0500 135.181.77.57:36558 -> 128.59.65.213:
3389 6 1930 17-Dec-2020 18:53:37 GMT-
0500 135.181.77.57:36567 -> 128.59.154.255:
3389 6 2741 17-Dec-2020 18:53:37 GMT-
0500 135.181.77.57:36894 -> 128.59.154.100:
3389 6 1653 17-Dec-2020 18:53:38 GMT-
0500 135.181.77.57:38467 -> 128.59.65.213:
3389 6 1946 17-Dec-2020 18:53:40 GMT-
0500 135.181.77.57:40849 -> 128.59.154.255:
3389 6 2512 17-Dec-2020 18:53:40 GMT-
0500 135.181.77.57:41204 -> 128.59.246.143:
3389 6 2679 17-Dec-2020 18:53:41 GMT-
0500 135.181.77.57:42269 -> 128.59.207.63:
3389 6 2807 17-Dec-2020 18:53:41 GMT-
0500 135.181.77.57:42714 -> 128.59.65.213:
3389 6 2033 17-Dec-2020 18:53:42 GMT-
0500 135.181.77.57:43265 -> 128.59.246.143:
3389 6 2299 Attempts continue…