Strange traffic from Exchange Server - is this a virus/trojan or normal Exchange traffic?

My XP personal firewall log shows some strange entries from an
Exchange Server outside of my control.

I have read http://www.petri.co.il/ports_used_by_exchange.htm
but cannot find anything that can account for this traffic pattern.

Basically, it seems to hit an increasing number of ports between
10,000 and 65,000, then start over again. Takes a few days to
go through the whole range. Small sample below.

Source port is an increasing range. Destination ports are - among
others - 1108, 1518, 1091, 1082, 1088, 1067, 1191, 1306, etc.

Mind you, this is from within a corporate firewall.

Is this normal, and if so, what service could be causing it?

???

TIA,

Joergen Bech



---snip--- (source/dest addresses changed to protect the
innocent/guilty):
---snip---
#Version: 1.5
#Software: Microsoft Windows Firewall
#Time Format: Local
#Fields: date time action protocol src-ip dst-ip src-port dst-port
size tcpflags tcpsyn tcpack tcpwin icmptype icmpcode info path
---snip---
2005-03-04 13:24:03 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 15404 1306 36 - - - - - - - RECEIVE
2005-03-04 13:24:03 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 15453 1306 36 - - - - - - - RECEIVE
2005-03-04 13:25:04 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 15569 1306 36 - - - - - - - RECEIVE
2005-03-04 13:25:04 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 15618 1306 36 - - - - - - - RECEIVE
2005-03-04 13:26:05 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 15793 1306 36 - - - - - - - RECEIVE
2005-03-04 13:26:05 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 15841 1306 36 - - - - - - - RECEIVE
2005-03-04 13:27:06 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 15932 1306 36 - - - - - - - RECEIVE
2005-03-04 13:27:06 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 15980 1306 36 - - - - - - - RECEIVE
2005-03-04 13:28:07 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16066 1306 36 - - - - - - - RECEIVE
2005-03-04 13:28:07 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16114 1306 36 - - - - - - - RECEIVE
2005-03-04 13:29:08 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16200 1306 36 - - - - - - - RECEIVE
2005-03-04 13:29:08 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16248 1306 36 - - - - - - - RECEIVE
2005-03-04 13:30:09 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16356 1306 36 - - - - - - - RECEIVE
2005-03-04 13:30:09 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16406 1306 36 - - - - - - - RECEIVE
2005-03-04 13:31:10 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16502 1306 36 - - - - - - - RECEIVE
2005-03-04 13:31:10 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16551 1306 36 - - - - - - - RECEIVE
2005-03-04 13:32:11 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16638 1306 36 - - - - - - - RECEIVE
2005-03-04 13:32:11 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16687 1306 36 - - - - - - - RECEIVE
2005-03-04 13:33:12 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16792 1306 36 - - - - - - - RECEIVE
2005-03-04 13:33:12 DROP UDP <src>.<src>.<src>.<src>
<dst>.<dst>.<dst>.<dst> 16840 1306 36 - - - - - - - RECEIVE


0
Joergen
3/4/2005 1:21:29 PM
exchange.admin 57650 articles. 2 followers. Follow

3 Replies
295 Views

Similar Articles

[PageSpeed] 23

You can either use ETHEREAL network sniffer or some of utilities (like
TDIMON) from www.sysinternals.com to find what is going on. Also use the
Task Manager to check what processes are running.

"Joergen Bech @" wrote:

> My XP personal firewall log shows some strange entries from an
> Exchange Server outside of my control.
>
> I have read http://www.petri.co.il/ports_used_by_exchange.htm
> but cannot find anything that can account for this traffic pattern.
>
> Basically, it seems to hit an increasing number of ports between
> 10,000 and 65,000, then start over again. Takes a few days to
> go through the whole range. Small sample below.
>
> Source port is an increasing range. Destination ports are - among
> others - 1108, 1518, 1091, 1082, 1088, 1067, 1191, 1306, etc.
>
> Mind you, this is from within a corporate firewall.
>
> Is this normal, and if so, what service could be causing it?
>
> ???
>
> TIA,
>
> Joergen Bech
>
> ---snip--- (source/dest addresses changed to protect the
> innocent/guilty):
> ---snip---
> #Version: 1.5
> #Software: Microsoft Windows Firewall
> #Time Format: Local
> #Fields: date time action protocol src-ip dst-ip src-port dst-port
> size tcpflags tcpsyn tcpack tcpwin icmptype icmpcode info path
> ---snip---
> 2005-03-04 13:24:03 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 15404 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:24:03 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 15453 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:25:04 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 15569 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:25:04 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 15618 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:26:05 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 15793 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:26:05 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 15841 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:27:06 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 15932 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:27:06 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 15980 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:28:07 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16066 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:28:07 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16114 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:29:08 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16200 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:29:08 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16248 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:30:09 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16356 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:30:09 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16406 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:31:10 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16502 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:31:10 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16551 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:32:11 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16638 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:32:11 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16687 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:33:12 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16792 1306 36 - - - - - - - RECEIVE
> 2005-03-04 13:33:12 DROP UDP <src>.<src>.<src>.<src>
> <dst>.<dst>.<dst>.<dst> 16840 1306 36 - - - - - - - RECEIVE

0
kpalagin (1838)
3/4/2005 2:39:16 PM
Please Ultra Network Sniffer from
http://www.gjpsoft.com/UltraNetSniffer/ to check your network.

0
3/13/2005 2:21:23 PM
Joergen,

Did you ever figure this out? We're having almost the exact sam
symptoms. I
SPAN'ed our Xchange Srvr port and ran Ethereal to capture the data
but it 
basically told us what we knew .. that we have high numbered xchang
ports t
alking to random hosts we don't control (although the same ones appea
over 
and over) on the udp ports you mentioned below. The data payloa
consists of
8 bytes with a consistent Hex value of 90 28 90 02 cb 44 f9 77.

Anybody?

thanks - jaso

--
jevansau9
-----------------------------------------------------------------------
jevansau99's Profile: http://www.msusenet.com/member.php?userid=82
View this thread: http://www.msusenet.com/t-216718

0
4/28/2005 8:54:22 PM
Reply:

Similar Artilces:

Exchange 5.5 to Exchange 2000 Swing Method
H We have upgraded a exchange 5.5 server to Exchange 2000 with a swing method Everything went ok but it seems that the active directory and the exchange organisation still have traces of the swing server because we are receiving warnings the event viewer application (ID:9318) about the swing server In the Exchange manager under the servers we still see the swing server there but it is greyd out and we are unable to delete it from there My question is how can i clean up my active directory and my exchange organisation of that server Thank you Did you remove Exchange from the old server by...

How to filter previous distribtion list in Exchange 2003
We are doing the migration. We are trying to create some address view to filter distribtion groups which are created from Exchange 5.5 before according to the following KB (e.g. create an extra item called company to filter it from Exchange 5.5 address book view automatically before) http://support.microsoft.com/default.aspx?scid=kb;en-us;262968 However, we don't know how to filter because we cannot find the company from the new distribution group, how to do? ...

Exchange upgrade from 5.5 to 2003
I have a 2003 mixed-mode domain with some NT servers with Exchange 5.5. I now would like to upgrade Exchange to 2003 and go to a native 2003 domain. Reading about the Exchange upgrade it sounds like you have to go to native mode first so that you can upgrade the schema with the Exchange fields. If that's the case this is what I'm looking at: 1. Upgrade all servers to 2000/2003. All Exchange servers will be 2000 since Exchange 5.5 won't run on 2003 2. Raise the functional level to 2000 native 3. Upgrade the schema for Exchange 2000/2003. 4. Upgrade all Exchange to 2000/2003. Doe...

2 MX records to two different Mail Servers
This is the scenario so please do not change it or make recommendation for the change...all hypothetical setup. I want to have two Exchange Servers at two different location to answer Internet Mail requests. These locations are NOT linked in anyway, but WILL use the same public DNS name for mail. For example, COMPANY.COM. If I have COMPANY.COM MX records pointing to two different IP Address (the two locations - I assume by MX weight records), will the mail arrive at the destination hosting the actual user mailbox? I have UserA@COMPANY.COM. Mail is destined to him - was not found on...

Exchange administration rights
Hi Everyone We would like to look at a more granular way of granting rights to some of the administrators/helpdesk operators here. For example - we would like to give one lady rights to link foreign domain accounts to exchange mailboxes. At the moment we can only give this right by making her a full admin. Can anyone suggest some reading material on assigning these type of rights etc or briefly explain how I could go about assigning these in a more granular way? Thanks for the help Regards Brendon ...

TCP/IP connection was unexpectedly terminated by the server.
I get this error message from time to time. I have several accounts and it seems that it is always the first one when trying to connect is when I get this error. Any hints. I'v checked my Norton Antivirus email scan and it is not active so that's not it. Thanks, Ray What kind of Internet connection do you have, and if you open a web browser before opening Outlook, and connect, does the problem occur? Raymond Taie wrote: > I get this error message from time to time. I have > several accounts and it seems that it is always the first > one when trying to connect is wh...

How do I set up multiple email domains in Exchange 2003 Std
Hi, We have multiple divisions in our company and each division has its own email address i.e. abc.com, xyz.com, etc. Some employees have multiple email addresses in these domains i.e. sam@abc.com, sam@xyz.com, etc. Could someone give me pointers on a KB or 3rd party article that covers how to set this up in Exchange 2003. -- Thanks, Sam Hi, This should help: http://www.msexchange.org/tutorials/MF010.html Leif "Sam" <Sam@discussions.microsoft.com> wrote in message news:57BA97FA-C8C6-4BFB-BA57-B66EFC318B4C@microsoft.com... > Hi, > > We have multiple divisio...

Small Business Server 4.5 / Exchange Server Deleted Mailbox
Does anyone know how to recover a deleted recipient mailbox in the Exchange server version that comes with Small Business Server 4.5? ...

Need help configurig outlook 2003 client for use wiht exchange server using outlook web access
Hello, Here is my problem. I am trying to configure Outlook 2003 to access an exchange server. The IT person gave me the following information. server: https://email.domain.com/exchange user name: XXXX\xxxxx I entered these two as given to me in the exchange server settings. However when i try to connect or check names I get an error message saying outlook could not log on. I also am not asked for my password or given a place to enter the password. Before you tell me that it can not be done, I have used the server and user name above to connect and access the exchange server wiht Microsof...

Exchange 2007 linked mailbox
Hello all We are running Exchange 2007 sp2, there are a few mailboxes that are showing up as "linked" mailboxes. I read a blog post about this, and a possible fix for this issue is to locate the user account using adsiedit and change the msExchRecipientTypeDetails from 2 to 1. When I do this all the mailboxes that showed up as linked, now show up as a regular mailbox, so it appears that changing the attribute worked, but after a day or two the mailboxes go back to being linked and the attribute changes from a 2 back to a 1. Any thoughts on what could be causing ...

my server keeps changing
whenever I go into outlook, one of my mail accounts keeps getting screwed up. I have an Imap account that I receive in outlook. The server always seems to revert back to "localhost" and I have to go into the properties tab and fix it. I hit apply and all that, but if I exit outlook and come back again, it changes to the "localhost" why is that? -- Lisa Melnick Disable Email scanning in your AV program. "Lisa Melnick" <lisamel@optonline.net> wrote in message news:NkMqb.3807$Ex1.2262796@news4.srv.hcvlny.cv.net... > whenever I go into outlook, one of m...

server crash during payroll checks
The server crash after paychecks printed but before I could post the payroll. I cannot get into the payroll/paychecks "Checks are currently being processed" I need to stop the old process some how. -- SPR ...

Exchange (2003) / Usenet Access...
Exchange (2003) / Usenet Access... Situation: Our office has an exchange server that users primarily use remotely by OWA. All the users have access to the public folders via OWA. Now what we would like to do is some how provide "Usenet" access. The company has a Usenet account and would some how like to pipe that into Exchange so that users can look at our exchange server for their Usenet needs. What we use to do is just let the users have the server address of our Usenet server and account user id and password. We no longer what to do this and would like to have th...

Exchange 2007 transport rule #2
Hello all I need to crerate a transport rule that will display a disclamer text in all outbound emails. Adding in the text part is a no brainer, but i also need to add in the disclamer a .gif image, but i dont know how i can add the image to the disclamer. Thanks ...

Exchange Tool for DST
How fast is the script running for some of your enviornments? I have roughly 300 to 350 mailboxes on a single server. Some users rely heavily on their calendar, and OWA, others don't use their calendars much at all. What type of perfomance hit can I expect on my exchange server while the script is running? Do users need to be logged out of their mailboxes while the script runs? Depends on the number of users, the number of calendar items in the affected period that need to be rebased, the number of attendees in each meeting (because meeting updates will be sent for each meeting...

Exchange Rates in Great Plains
We use eConnect to send invoices and supplier invoices from our order processing software, using <PMTransactionType> and <RMTransactionType> XML files. We have had reports from customers that when an Exchange Rate <XCHGRATE> is exported it's the incorrect divisor (ie. We export Conversion to Base currency rate), however others have said it's fine. Is there a setting in Great Plains that determines whether it wants the rate as Conversion To Base, or Conversion From Base? ...

How to move my server
I have RMS 2.0 and SQL server 2005. I have my server installed on my register1. I don't think that my register computer has enough juice to host my server and my database. I have been getting 100% cpu usage while running the programs etc. I have also had a lot of time out errors from my printer. I would like to turn a different computer into the server and am hoping that someone could help me through that process. I am a novice, so please keep it very simple. I am not very familiar with sql server and have no idea what to do with it except to make sure that it is running if my conne...

Checking DNS Server settings
Hi, Have recently had some problems with DNS lookups. A restart of DNS Server service helped. Now checked a bit further and remembered an old issue we had here. Clients were set with 2 x DNS entries. First to our SBS then to our Internet router. (This was wrong and resulted in clients swapping over to router for DNS, but not swapping back). Checked LAN settings for SBS and saw that here was also 2 x DNS enties. First to the internal IP of the server itself, next to Internet router. Have Removed the router entry so that now, in LAN DNS have only the IP of the server itself. ...

SQL Server 2000 Virtual_Device question
Hi, My SQL Server 2000 log has recorded backup failed info: BACKUP failed to complete the command BACKUP DATABASE [GoodDb] TO VIRTUAL_DEVICE='{FB41ED2E-2437-4F6A-8FFC-AB42B43A5AA5}49' WITH SNAPSHOT,BUFFERCOUNT=1,BLOCKSIZE=1024 How do I find the VIRTUAL_DEVICE '{FB41ED2E-2437-4F6A-8FFC-AB42B43A5AA5}49' ? Thanks for help. Jason ...

No available exchange tasks
We upgraded to Exchange 2003 from 2000. We have a server with AD installed on it and another server with Exchange 2003 on it that is not a DC. When I am on the DC and click on the Exchange Tasks in AD, I get the following: There are no available tasks. ID c103c50a Mircosoft Active Directory - Exchange Extension Thanks You may want to install the Exchange management tools from the CD...not the server, just the tools. Bob "Aaron" <anonymous@discussions.microsoft.com> wrote in message news:044101c48b19$54a80fc0$a601280a@phx.gbl... > We upgraded to Exchange 2003 from ...

How to setup policy for Exchange/Outlook 2003
I'm looking for a way to have all messages in Outlook 2003 Sent Items folder auto delete after 30 days. I know a policy can be applied via mail retention policy for the entire information store, I'm just looking for a way to delete items after 30 days in Sent Items. -- ITJTR Take a look at http://www.msexchange.org/tutorials/MF012.html for a tutorial for Exchange 2000. It's the same for E2K3. Jeff Guillet, MCSE "ITJTR" wrote: > I'm looking for a way to have all messages in Outlook 2003 Sent Items folder > auto delete after 30 days. I know a policy c...

Is the MS Exchange 2003 GAL an Active Directory Object?
MS Exchange 2003 uses Address Lists such as the Global Address List. I know that this GAL is generated and updated by RUS (Recipient Update Service) and stored in the Active Directory. But is the GAL an Active Directory Object? If not what is this from the Active Directory point of view? The GAL is fundamentally an LDAP query against data stored in AD objects. "Julien" <Julien@discussions.microsoft.com> wrote in message news:91C405F8-D3AF-43D8-B6DB-D6F4C731435B@microsoft.com... > MS Exchange 2003 uses Address Lists such as the Global Address List. > I know that this ...

Microsoft Project Server Web Logo
How do I change the MS Project Server Logo to my company logo? ...

outlook clients Searching deleted exchange server
I have two exchange servers(INDIAN and HOBDC) in my site(IILHO) , i transferred all mailboxes and public folders from HOBDC to INDIAN and i deleted HOBDC from site, but when i open outlook and public folder outlook is searching for deleted server(HOBDC). In registry also it is creating entry for HOBDC in profile. So if i switch off deleted exchange server (HOBDC) clients are hanging, because clients are searching for HOBDC, particularly for public folders kindly suggest me the right solution for this problem regards Nagaraju Are you sure that you transferred all public folders? Di...

Exchange Admin Account for Backup Software
I need help either finding my Exchange Administrator user or designating a user with proper permissions to access my Exchange mailbox store via my backup software (Veritas Backup Exec 10). I've tried the Delegate Control function in Exchange System Manager to no avail. I'm only getting half of the value of my backup solution until I get this figured out. Any ideas? Daniel On Tue, 10 May 2005 09:45:44 -0700, "Daniel J. Spencer" <dspencer@rlmin.org> wrote: >I need help either finding my Exchange Administrator user or designating >a user with proper permiss...