Within the superhub firewall log, I am getting a port scan showing below:
Date:Fri 17 Aug
Time:19:57
Source IP:194.168.4.100
Target Port Number:58600
Count:27
Event Description:TCP- or UDP-based
Checking ip address reveals this below:
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See
http://www.ripe.net/db/support/db-terms-conditions.pdf
% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '194.168.4.0 - 194.168.5.255'
inetnum: 194.168.4.0 - 194.168.5.255
netname: CABLEOL
descr: Cable Online Ltd
country: GB
admin-c: NNMC1-RIPE
tech-c: NNMC1-RIPE
status: ASSIGNED PA
mnt-by: AS5089-MNT
remarks: INFRA-AW
source: RIPE # Filtered
role: NTLI Network Management Centre
address: NTL Internet
address: Test
address: Winchester
address: Hampshire
address: SO21 2QA
phone: +44 1633710142
admin-c: MH22007-RIPE
admin-c: NR731-RIPE
admin-c: CW1083-RIPE
tech-c: MH22007-RIPE
tech-c: CW1083-RIPE
nic-hdl: NNMC1-RIPE
mnt-by: AS5089-MNT
source: RIPE # Filtered
% Information related to '194.168.0.0/16AS5089'
route: 194.168.0.0/16
descr: NTL-UK-IP-BLOCK-1
origin: AS5089
mnt-by: AS5089-MNT
source: RIPE # Filtered
% This query was served by the RIPE Database Query Service version 1.19.5 (WHOIS4)
Any ideas why would I get port scanned for this?
Thanks,
Boabyboy