This is an automated message from Columbia University IT Security. You are
receiving it because you are listed as the abuse contact in WHOIS for the machine
referred to below. This machine either attempted to gain unauthorized
access to one or more machines, or was scanning the network at Columbia
University.
It is possible that this alert is the result of a reflection attack against your network with a spoofed origin matching Columbia University’s network.
Details are provided below. Please take all necessary
steps to mitigate such attacks, or ignore this notice if this traffic is spoofed.
If you have received this message in error, or if this incident
reported is inappropriate, please contact
security@columbia.edu so that we can update our procedures. Please include the entire
body of this message.
Thank You.
Columbia University IT Security
security@columbia.edu Name: static.57.77.181.135.clients.your-server.de
Address: 135.181.77.57
Incident type: 3389/tcp
First attempt: 19-dec-2020 19:50:00 GMT-0500
Last attempt: 19-dec-2020 19:50:00 GMT-0500
Total attempts: 457
19-Dec-2020 19:49:58 GMT-
0500 135.181.77.57:47699 -> 128.59.81.205:
3389 6 1853 19-Dec-2020 19:49:53 GMT-
0500 135.181.77.57:42149 -> 128.59.81.205:
3389 6 1878 19-Dec-2020 19:49:56 GMT-
0500 135.181.77.57:45785 -> 128.59.81.205:
3389 6 1924 19-Dec-2020 19:49:51 GMT-
0500 135.181.77.57:40308 -> 128.59.81.205:
3389 6 1899 19-Dec-2020 19:49:55 GMT-
0500 135.181.77.57:43977 -> 128.59.81.205:
3389 6 1847 19-Dec-2020 19:49:50 GMT-
0500 135.181.77.57:38651 -> 128.59.180.83:
3389 6 1518 19-Dec-2020 19:49:57 GMT-
0500 135.181.77.57:45146 -> 128.59.150.198:
3389 6 46 19-Dec-2020 19:49:54 GMT-
0500 135.181.77.57:43284 -> 128.59.104.175:
3389 6 1552 19-Dec-2020 19:49:53 GMT-
0500 135.181.77.57:42149 -> 128.59.81.205:
3389 6 1498 19-Dec-2020 19:49:57 GMT-
0500 135.181.77.57:46950 -> 128.59.150.198:
3389 6 1651 19-Dec-2020 19:50:02 GMT-
0500 135.181.77.57:47825 -> 128.59.178.95:
3389 6 276 19-Dec-2020 19:49:55 GMT-
0500 135.181.77.57:43977 -> 128.59.81.205:
3389 6 1795 19-Dec-2020 19:49:58 GMT-
0500 135.181.77.57:47699 -> 128.59.81.205:
3389 6 1715 19-Dec-2020 19:49:58 GMT-
0500 135.181.77.57:46952 -> 128.59.104.175:
3389 6 1157 19-Dec-2020 19:50:01 GMT-
0500 135.181.77.57:51403 -> 128.59.81.205:
3389 6 1853 19-Dec-2020 19:50:05 GMT-
0500 135.181.77.57:55151 -> 128.59.81.205:
3389 6 1899 19-Dec-2020 19:50:00 GMT-
0500 135.181.77.57:49512 -> 128.59.81.205:
3389 6 1874 19-Dec-2020 19:50:00 GMT-
0500 135.181.77.57:47699 -> 128.59.81.205:
3389 6 46 19-Dec-2020 19:50:03 GMT-
0500 135.181.77.57:53349 -> 128.59.81.205:
3389 6 1916 19-Dec-2020 19:50:07 GMT-
0500 135.181.77.57:56997 -> 128.59.81.205:
3389 6 1086 19-Dec-2020 19:50:10 GMT-
0500 135.181.77.57:1382 -> 128.59.104.175:
3389 6 1203 19-Dec-2020 19:50:07 GMT-
0500 135.181.77.57:58049 -> 128.59.150.198:
3389 6 1882 19-Dec-2020 19:50:08 GMT-
0500 135.181.77.57:58469 -> 128.59.104.175:
3389 6 2755 19-Dec-2020 19:50:04 GMT-
0500 135.181.77.57:54302 -> 128.59.150.198:
3389 6 1651 19-Dec-2020 19:50:02 GMT-
0500 135.181.77.57:51736 -> 128.59.178.95:
3389 6 1508 19-Dec-2020 19:50:04 GMT-
0500 135.181.77.57:52724 -> 128.59.104.175:
3389 6 328 19-Dec-2020 19:50:04 GMT-
0500 135.181.77.57:54781 -> 128.59.104.175:
3389 6 1948 19-Dec-2020 19:50:08 GMT-
0500 135.181.77.57:58936 -> 128.59.81.205:
3389 6 1849 19-Dec-2020 19:50:10 GMT-
0500 135.181.77.57:1846 -> 128.59.81.205:
3389 6 1918 19-Dec-2020 19:50:13 GMT-
0500 135.181.77.57:5577 -> 128.59.81.205:
3389 6 1866 19-Dec-2020 19:50:06 GMT-
0500 135.181.77.57:56997 -> 128.59.81.205:
3389 6 1870 19-Dec-2020 19:50:11 GMT-
0500 135.181.77.57:3743 -> 128.59.81.205:
3389 6 1895 19-Dec-2020 19:50:10 GMT-
0500 135.181.77.57:1846 -> 128.59.81.205:
3389 6 1538 19-Dec-2020 19:50:13 GMT-
0500 135.181.77.57:5577 -> 128.59.81.205:
3389 6 1082 19-Dec-2020 19:50:10 GMT-
0500 135.181.77.57:1963 -> 128.59.178.95:
3389 6 1737 19-Dec-2020 19:50:12 GMT-
0500 135.181.77.57:3306 -> 128.59.104.175:
3389 6 1157 19-Dec-2020 19:50:12 GMT-
0500 135.181.77.57:3743 -> 128.59.81.205:
3389 6 986 19-Dec-2020 19:50:14 GMT-
0500 135.181.77.57:6504 -> 128.59.150.198:
3389 6 1234 19-Dec-2020 19:50:18 GMT-
0500 135.181.77.57:9324 -> 128.59.81.205:
3389 6 276 19-Dec-2020 19:50:14 GMT-
0500 135.181.77.57:5210 -> 128.59.104.175:
3389 6 46 19-Dec-2020 19:50:12 GMT-
0500 135.181.77.57:4600 -> 128.59.150.198:
3389 6 1852 19-Dec-2020 19:50:16 GMT-
0500 135.181.77.57:9324 -> 128.59.81.205:
3389 6 1920 19-Dec-2020 19:50:20 GMT-
0500 135.181.77.57:12967 -> 128.59.81.205:
3389 6 1872 19-Dec-2020 19:50:21 GMT-
0500 135.181.77.57:14889 -> 128.59.81.205:
3389 6 1893 19-Dec-2020 19:50:18 GMT-
0500 135.181.77.57:11156 -> 128.59.81.205:
3389 6 1853 19-Dec-2020 19:50:15 GMT-
0500 135.181.77.57:7450 -> 128.59.81.205:
3389 6 1899 19-Dec-2020 19:50:19 GMT-
0500 135.181.77.57:11914 -> 128.59.150.198:
3389 6 1800 19-Dec-2020 19:50:25 GMT-
0500 135.181.77.57:17282 -> 128.59.150.198:
3389 6 374 19-Dec-2020 19:50:25 GMT-
0500 135.181.77.57:18615 -> 128.59.81.205:
3389 6 1104 Attempts continue…