This is an automated message from Columbia University IT Security. You are
receiving it because you are listed as the abuse contact in WHOIS for the machine
referred to below. This machine either attempted to gain unauthorized
access to one or more machines, or was scanning the network at Columbia
University.
It is possible that this alert is the result of a reflection attack against your network with a spoofed origin matching Columbia University’s network.
Details are provided below. Please take all necessary
steps to mitigate such attacks, or ignore this notice if this traffic is spoofed.
If you have received this message in error, or if this incident
reported is inappropriate, please contact
security@columbia.edu so that we can update our procedures. Please include the entire
body of this message.
Thank You.
Columbia University IT Security
security@columbia.edu Name: static.57.77.181.135.clients.your-server.de
Address: 135.181.77.57
Incident type: 3389/tcp
First attempt: 27-dec-2020 17:25:00 GMT-0500
Last attempt: 27-dec-2020 17:30:00 GMT-0500
Total attempts: 956
27-Dec-2020 17:20:01 GMT-
0500 135.181.77.57:42931 -> 128.59.179.202:
3389 6 185 27-Dec-2020 17:20:02 GMT-
0500 135.181.77.57:43214 -> 128.59.179.202:
3389 6 185 27-Dec-2020 17:24:56 GMT-
0500 135.181.77.57:52345 -> 128.59.180.83:
3389 6 1138 27-Dec-2020 17:25:02 GMT-
0500 135.181.77.57:58913 -> 128.59.179.202:
3389 6 46 27-Dec-2020 17:25:02 GMT-
0500 135.181.77.57:1161 -> 128.59.207.80:
3389 6 1157 27-Dec-2020 17:24:56 GMT-
0500 135.181.77.57:53490 -> 128.59.146.172:
3389 6 2551 27-Dec-2020 17:24:55 GMT-
0500 135.181.77.57:51506 -> 128.59.179.202:
3389 6 1976 27-Dec-2020 17:25:03 GMT-
0500 135.181.77.57:59732 -> 128.59.146.172:
3389 6 374 27-Dec-2020 17:25:03 GMT-
0500 135.181.77.57:2766 -> 128.59.146.172:
3389 6 2551 27-Dec-2020 17:25:03 GMT-
0500 135.181.77.57:2139 -> 128.59.87.212:
3389 6 1062 27-Dec-2020 17:24:50 GMT-
0500 135.181.77.57:44799 -> 128.59.178.247:
3389 6 1060 27-Dec-2020 17:24:59 GMT-
0500 135.181.77.57:55881 -> 128.59.207.80:
3389 6 1986 27-Dec-2020 17:24:59 GMT-
0500 135.181.77.57:56764 -> 128.59.154.100:
3389 6 1766 27-Dec-2020 17:25:03 GMT-
0500 135.181.77.57:57996 -> 128.59.180.83:
3389 6 276 27-Dec-2020 17:25:03 GMT-
0500 135.181.77.57:1544 -> 128.59.160.191:
3389 6 374 27-Dec-2020 17:25:03 GMT-
0500 135.181.77.57:3536 -> 128.59.160.191:
3389 6 1946 27-Dec-2020 17:20:06 GMT-
0500 135.181.77.57:48844 -> 128.59.179.202:
3389 6 185 27-Dec-2020 17:25:06 GMT-
0500 135.181.77.57:6663 -> 128.59.87.212:
3389 6 1584 27-Dec-2020 17:25:06 GMT-
0500 135.181.77.57:4875 -> 128.59.146.172:
3389 6 46 27-Dec-2020 17:25:09 GMT-
0500 135.181.77.57:10548 -> 128.59.179.202:
3389 6 1966 27-Dec-2020 17:25:12 GMT-
0500 135.181.77.57:12275 -> 128.59.207.80:
3389 6 328 27-Dec-2020 17:25:07 GMT-
0500 135.181.77.57:6092 -> 128.59.154.100:
3389 6 276 27-Dec-2020 17:25:07 GMT-
0500 135.181.77.57:8126 -> 128.59.154.100:
3389 6 1842 27-Dec-2020 17:25:07 GMT-
0500 135.181.77.57:3469 -> 128.59.180.83:
3389 6 276 27-Dec-2020 17:25:10 GMT-
0500 135.181.77.57:11311 -> 128.59.87.212:
3389 6 1130 27-Dec-2020 17:25:07 GMT-
0500 135.181.77.57:8229 -> 128.59.180.83:
3389 6 1673 27-Dec-2020 17:25:10 GMT-
0500 135.181.77.57:9731 -> 128.59.160.191:
3389 6 46 27-Dec-2020 17:25:10 GMT-
0500 135.181.77.57:10200 -> 128.59.154.100:
3389 6 276 27-Dec-2020 17:25:10 GMT-
0500 135.181.77.57:5322 -> 128.59.178.95:
3389 6 230 27-Dec-2020 17:25:10 GMT-
0500 135.181.77.57:10044 -> 128.59.207.80:
3389 6 328 27-Dec-2020 17:20:14 GMT-
0500 135.181.77.57:58046 -> 128.59.179.202:
3389 6 185 27-Dec-2020 17:20:18 GMT-
0500 135.181.77.57:51923 -> 129.236.161.200:
3389 6 48 27-Dec-2020 17:20:21 GMT-
0500 135.181.77.57:4103 -> 129.236.161.200:
3389 6 52 27-Dec-2020 17:25:21 GMT-
0500 135.181.77.57:25255 -> 128.59.207.80:
3389 6 2761 27-Dec-2020 17:25:12 GMT-
0500 135.181.77.57:14403 -> 128.59.207.80:
3389 6 2758 27-Dec-2020 17:25:12 GMT-
0500 135.181.77.57:13717 -> 128.59.87.212:
3389 6 1020 27-Dec-2020 17:25:12 GMT-
0500 135.181.77.57:14167 -> 128.59.179.202:
3389 6 1787 27-Dec-2020 17:25:12 GMT-
0500 135.181.77.57:13855 -> 128.59.160.191:
3389 6 1155 27-Dec-2020 17:25:14 GMT-
0500 135.181.77.57:16198 -> 128.59.154.100:
3389 6 974 27-Dec-2020 17:25:21 GMT-
0500 135.181.77.57:25665 -> 128.59.179.202:
3389 6 1550 27-Dec-2020 17:25:22 GMT-
0500 135.181.77.57:27263 -> 128.59.146.172:
3389 6 2551 27-Dec-2020 17:25:15 GMT-
0500 135.181.77.57:15938 -> 128.59.87.212:
3389 6 230 27-Dec-2020 17:25:25 GMT-
0500 135.181.77.57:29692 -> 128.59.180.83:
3389 6 1178 27-Dec-2020 17:25:25 GMT-
0500 135.181.77.57:29279 -> 128.59.146.172:
3389 6 1091 27-Dec-2020 17:25:25 GMT-
0500 135.181.77.57:30424 -> 128.59.154.100:
3389 6 1768 27-Dec-2020 17:25:25 GMT-
0500 135.181.77.57:30479 -> 128.59.207.80:
3389 6 1896 27-Dec-2020 17:25:28 GMT-
0500 135.181.77.57:34601 -> 128.59.207.80:
3389 6 1948 27-Dec-2020 17:25:28 GMT-
0500 135.181.77.57:32547 -> 128.59.207.80:
3389 6 328 27-Dec-2020 17:25:25 GMT-
0500 135.181.77.57:28769 -> 128.59.179.202:
3389 6 46 Attempts continue…
27-Dec-2020 17:29:56 GMT-
0500 135.181.77.57:12862 -> 128.59.160.191:
3389 6 1534 27-Dec-2020 17:29:56 GMT-
0500 135.181.77.57:12744 -> 128.59.207.80:
3389 6 2032 27-Dec-2020 17:29:58 GMT-
0500 135.181.77.57:15728 -> 128.59.179.202:
3389 6 1905 27-Dec-2020 17:29:59 GMT-
0500 135.181.77.57:16838 -> 128.59.207.80:
3389 6 2758 27-Dec-2020 17:29:57 GMT-
0500 135.181.77.57:14834 -> 128.59.160.191:
3389 6 1894 27-Dec-2020 17:29:57 GMT-
0500 135.181.77.57:14992 -> 128.59.154.100:
3389 6 1784 27-Dec-2020 17:25:02 GMT-
0500 135.181.77.57:2319 -> 128.59.179.202:
3389 6 185 27-Dec-2020 17:25:02 GMT-
0500 135.181.77.57:2552 -> 128.59.179.202:
3389 6 185 27-Dec-2020 17:25:03 GMT-
0500 135.181.77.57:3065 -> 128.59.179.202:
3389 6 185 27-Dec-2020 17:30:07 GMT-
0500 135.181.77.57:27241 -> 128.59.154.100:
3389 6 1740 27-Dec-2020 17:30:07 GMT-
0500 135.181.77.57:27246 -> 128.59.160.191:
3389 6 1894 27-Dec-2020 17:30:01 GMT-
0500 135.181.77.57:18002 -> 128.59.104.64:
3389 6 374 27-Dec-2020 17:30:04 GMT-
0500 135.181.77.57:21467 -> 128.59.179.202:
3389 6 276 27-Dec-2020 17:30:01 GMT-
0500 135.181.77.57:19884 -> 128.59.146.172:
3389 6 2366 27-Dec-2020 17:30:01 GMT-
0500 135.181.77.57:19483 -> 128.59.87.212:
3389 6 1144 27-Dec-2020 17:30:04 GMT-
0500 135.181.77.57:23117 -> 128.59.154.100:
3389 6 1058 27-Dec-2020 17:30:04 GMT-
0500 135.181.77.57:23071 -> 128.59.160.191:
3389 6 1298 27-Dec-2020 17:30:01 GMT-
0500 135.181.77.57:18091 -> 128.59.179.202:
3389 6 230 27-Dec-2020 17:25:09 GMT-
0500 135.181.77.57:6719 -> 129.236.161.200:
3389 6 100 27-Dec-2020 17:30:09 GMT-
0500 135.181.77.57:28054 -> 128.59.146.172:
3389 6 46 27-Dec-2020 17:30:15 GMT-
0500 135.181.77.57:35016 -> 128.59.104.64:
3389 6 328 27-Dec-2020 17:30:10 GMT-
0500 135.181.77.57:28682 -> 128.59.87.212:
3389 6 230 27-Dec-2020 17:30:11 GMT-
0500 135.181.77.57:32835 -> 128.59.178.95:
3389 6 1874 27-Dec-2020 17:30:10 GMT-
0500 135.181.77.57:30238 -> 128.59.207.80:
3389 6 1986 27-Dec-2020 17:30:10 GMT-
0500 135.181.77.57:30368 -> 128.59.178.95:
3389 6 1030 27-Dec-2020 17:30:16 GMT-
0500 135.181.77.57:38299 -> 128.59.146.172:
3389 6 2583 27-Dec-2020 17:30:10 GMT-
0500 135.181.77.57:30418 -> 128.59.104.64:
3389 6 1986 27-Dec-2020 17:30:11 GMT-
0500 135.181.77.57:32920 -> 128.59.104.64:
3389 6 2761 27-Dec-2020 17:25:21 GMT-
0500 135.181.77.57:25170 -> 128.59.179.202:
3389 6 133 27-Dec-2020 17:25:21 GMT-
0500 135.181.77.57:25393 -> 128.59.179.202:
3389 6 185 27-Dec-2020 17:30:17 GMT-
0500 135.181.77.57:39550 -> 128.59.160.191:
3389 6 1344 27-Dec-2020 17:30:17 GMT-
0500 135.181.77.57:39771 -> 128.59.87.212:
3389 6 1783 27-Dec-2020 17:30:21 GMT-
0500 135.181.77.57:44773 -> 128.59.87.212:
3389 6 1741 27-Dec-2020 17:30:17 GMT-
0500 135.181.77.57:40279 -> 128.59.146.172:
3389 6 2551 27-Dec-2020 17:30:18 GMT-
0500 135.181.77.57:38651 -> 128.59.207.80:
3389 6 328 27-Dec-2020 17:30:11 GMT-
0500 135.181.77.57:32724 -> 128.59.178.247:
3389 6 1872 27-Dec-2020 17:30:18 GMT-
0500 135.181.77.57:40722 -> 128.59.207.80:
3389 6 2709 27-Dec-2020 17:30:16 GMT-
0500 135.181.77.57:37856 -> 128.59.104.64:
3389 6 2427 27-Dec-2020 17:30:18 GMT-
0500 135.181.77.57:40843 -> 128.59.104.64:
3389 6 2718 27-Dec-2020 17:25:26 GMT-
0500 135.181.77.57:31440 -> 128.59.179.202:
3389 6 133 27-Dec-2020 17:30:27 GMT-
0500 135.181.77.57:51682 -> 128.59.154.100:
3389 6 926 27-Dec-2020 17:30:25 GMT-
0500 135.181.77.57:50168 -> 128.59.207.80:
3389 6 2709 27-Dec-2020 17:30:27 GMT-
0500 135.181.77.57:52346 -> 128.59.207.80:
3389 6 2758 27-Dec-2020 17:30:27 GMT-
0500 135.181.77.57:52718 -> 128.59.104.64:
3389 6 1978 27-Dec-2020 17:30:26 GMT-
0500 135.181.77.57:50440 -> 128.59.146.172:
3389 6 1981 27-Dec-2020 17:30:32 GMT-
0500 135.181.77.57:57858 -> 128.59.160.191:
3389 6 1093 27-Dec-2020 17:30:32 GMT-
0500 135.181.77.57:56642 -> 128.59.146.172:
3389 6 374 27-Dec-2020 17:30:32 GMT-
0500 135.181.77.57:58522 -> 128.59.146.172:
3389 6 2551 27-Dec-2020 17:30:33 GMT-
0500 135.181.77.57:59633 -> 128.59.154.100:
3389 6 924 Attempts continue…