This is an automated message from Columbia University IT Security. You are
receiving it because you are listed as the abuse contact in WHOIS for the machine
referred to below. This machine either attempted to gain unauthorized
access to one or more machines, or was scanning the network at Columbia
University.
It is possible that this alert is the result of a reflection attack against your network with a spoofed origin matching Columbia University’s network.
Details are provided below. Please take all necessary
steps to mitigate such attacks, or ignore this notice if this traffic is spoofed.
If you have received this message in error, or if this incident
reported is inappropriate, please contact
security@columbia.edu so that we can update our procedures. Please include the entire
body of this message.
Thank You.
Columbia University IT Security
security@columbia.edu Name: static.57.77.181.135.clients.your-server.de
Address: 135.181.77.57
Incident type: 3389/tcp
First attempt: 22-dec-2020 19:10:00 GMT-0500
Last attempt: 22-dec-2020 19:10:00 GMT-0500
Total attempts: 433
22-Dec-2020 19:09:43 GMT-
0500 135.181.77.57:51561 -> 128.59.81.205:
3389 6 2072 22-Dec-2020 19:09:50 GMT-
0500 135.181.77.57:16965 -> 128.59.180.83:
3389 6 1998 22-Dec-2020 19:09:49 GMT-
0500 135.181.77.57:10767 -> 128.59.150.198:
3389 6 2082 22-Dec-2020 19:09:56 GMT-
0500 135.181.77.57:29575 -> 128.59.235.33:
3389 6 1993 22-Dec-2020 19:09:57 GMT-
0500 135.181.77.57:31029 -> 128.59.29.175:
3389 6 1950 22-Dec-2020 19:09:51 GMT-
0500 135.181.77.57:19683 -> 128.59.160.191:
3389 6 2078 22-Dec-2020 19:10:03 GMT-
0500 135.181.77.57:25368 -> 128.59.150.55:
3389 6 555 22-Dec-2020 19:09:55 GMT-
0500 135.181.77.57:29654 -> 128.59.81.205:
3389 6 2048 22-Dec-2020 19:10:05 GMT-
0500 135.181.77.57:1626 -> 128.59.160.191:
3389 6 2111 22-Dec-2020 19:10:05 GMT-
0500 135.181.77.57:56664 -> 128.59.178.95:
3389 6 1873 22-Dec-2020 19:10:14 GMT-
0500 135.181.77.57:55132 -> 128.59.180.83:
3389 6 276 22-Dec-2020 19:10:28 GMT-
0500 135.181.77.57:11106 -> 128.59.144.198:
3389 6 92 22-Dec-2020 19:10:10 GMT-
0500 135.181.77.57:13845 -> 128.59.154.100:
3389 6 1916 22-Dec-2020 19:10:10 GMT-
0500 135.181.77.57:13883 -> 128.59.235.33:
3389 6 2096 22-Dec-2020 19:10:10 GMT-
0500 135.181.77.57:13917 -> 128.59.81.205:
3389 6 1968 22-Dec-2020 19:10:09 GMT-
0500 135.181.77.57:13917 -> 128.59.81.205:
3389 6 2066 22-Dec-2020 19:10:24 GMT-
0500 135.181.77.57:59673 -> 128.59.81.205:
3389 6 2048 22-Dec-2020 19:10:39 GMT-
0500 135.181.77.57:45549 -> 128.59.71.127:
3389 6 277 22-Dec-2020 19:10:19 GMT-
0500 135.181.77.57:40887 -> 128.59.180.83:
3389 6 1865 22-Dec-2020 19:10:24 GMT-
0500 135.181.77.57:59181 -> 128.59.154.100:
3389 6 2004 22-Dec-2020 19:10:24 GMT-
0500 135.181.77.57:59499 -> 128.59.235.33:
3389 6 2194 22-Dec-2020 19:10:24 GMT-
0500 135.181.77.57:1187 -> 128.59.29.175:
3389 6 2052 22-Dec-2020 19:10:25 GMT-
0500 135.181.77.57:59673 -> 128.59.81.205:
3389 6 1950 22-Dec-2020 19:10:33 GMT-
0500 135.181.77.57:30320 -> 128.59.178.95:
3389 6 2154 22-Dec-2020 19:10:46 GMT-
0500 135.181.77.57:28508 -> 128.59.180.83:
3389 6 276 22-Dec-2020 19:10:46 GMT-
0500 135.181.77.57:4166 -> 128.59.71.118:
3389 6 92 22-Dec-2020 19:10:32 GMT-
0500 135.181.77.57:17481 -> 128.59.160.191:
3389 6 1899 22-Dec-2020 19:10:53 GMT-
0500 135.181.77.57:46965 -> 128.59.154.100:
3389 6 230 22-Dec-2020 19:10:53 GMT-
0500 135.181.77.57:47287 -> 128.59.235.33:
3389 6 328 22-Dec-2020 19:10:53 GMT-
0500 135.181.77.57:47397 -> 128.59.81.205:
3389 6 230 22-Dec-2020 19:10:47 GMT-
0500 135.181.77.57:57166 -> 128.59.71.127:
3389 6 1328 22-Dec-2020 19:10:49 GMT-
0500 135.181.77.57:59717 -> 128.59.154.255:
3389 6 1154 22-Dec-2020 19:10:40 GMT-
0500 135.181.77.57:48286 -> 128.59.29.175:
3389 6 2126 22-Dec-2020 19:10:50 GMT-
0500 135.181.77.57:17889 -> 128.59.180.83:
3389 6 1727 22-Dec-2020 19:10:50 GMT-
0500 135.181.77.57:18608 -> 128.59.160.211:
3389 6 1617 22-Dec-2020 19:10:50 GMT-
0500 135.181.77.57:5481 -> 128.59.150.55:
3389 6 1060 22-Dec-2020 19:10:39 GMT-
0500 135.181.77.57:47397 -> 128.59.81.205:
3389 6 2066 22-Dec-2020 19:10:49 GMT-
0500 135.181.77.57:11172 -> 128.59.150.198:
3389 6 1851 22-Dec-2020 19:10:59 GMT-
0500 135.181.77.57:39512 -> 128.59.29.175:
3389 6 898 22-Dec-2020 19:10:56 GMT-
0500 135.181.77.57:38597 -> 128.59.235.33:
3389 6 1333 22-Dec-2020 19:10:57 GMT-
0500 135.181.77.57:38276 -> 128.59.154.100:
3389 6 1222 22-Dec-2020 19:11:03 GMT-
0500 135.181.77.57:56895 -> 128.59.54.208:
3389 6 904 22-Dec-2020 19:11:14 GMT-
0500 135.181.77.57:55210 -> 128.59.144.44:
3389 6 265 22-Dec-2020 19:11:10 GMT-
0500 135.181.77.57:36241 -> 128.59.71.127:
3389 6 217 22-Dec-2020 19:10:56 GMT-
0500 135.181.77.57:38778 -> 128.59.81.205:
3389 6 1324 22-Dec-2020 19:10:56 GMT-
0500 135.181.77.57:38778 -> 128.59.81.205:
3389 6 1324 22-Dec-2020 19:11:08 GMT-
0500 135.181.77.57:19817 -> 128.59.207.27:
3389 6 734 22-Dec-2020 19:11:08 GMT-
0500 135.181.77.57:17237 -> 128.59.38.202:
3389 6 820 22-Dec-2020 19:11:08 GMT-
0500 135.181.77.57:17093 -> 128.59.178.95:
3389 6 909 Attempts continue…