What Are They Looking For?


For the past few weeks, our pseudo SMTP server has been receiving numerous strange connections that I do not understand. Overall attempts to deliver mail are down, but we are seeing many of these:

1. on port 55628|10:09:08




1. Closed.|10:09:08

from many different IP addresses and locations. Obviously it is a BOT Net, but what are they looking for? There is no MAIL FROM: or RCPT TO:, just EHLO, HELO, and QUIT.

J.A. Coutts

