I am getting suspicious activity on Port 445 from the following IP's which a from TC ( customers?)
What should I do? The following 9 are from port 445
9/8/2008 7:53:53 PM 121.14.136.143
9/8/2008 8:00:54 PM 121.73.125.79 lookup from whois below
9/8/2008 8:11:09 PM 121.73.125.43
9/8/2008 8:20:27 PM 121.73.22.193
9/8/2008 8:32:11 PM 121.219.25.195
9/8/2008 8:49:04 PM 121.63.146.18
121.73.135.30
121.73.11.203
121.73.6.147
P Information for 121.73.125.79
| IP Location: | |
| IP Address: | 121.73.125.79 |
| Blacklist Status: | Clear |
9/8/2008 7:53:53 PM Intrusion.Win.DCOM.exploit 121.14.136.143 TCP 135
9/8/2008 8:00:54 PM Intrusion.Win.DCOM.exploit 121.73.125.79 TCP 135
9/8/2008 8:11:09 PM Intrusion.Win.DCOM.exploit 121.73.125.43 TCP 135
9/8/2008 8:20:27 PM Intrusion.Win.DCOM.exploit 121.73.22.193 TCP 135
9/8/2008 8:32:11 PM Intrusion.Win.DCOM.exploit 121.219.25.195 TCP 135
9/8/2008 8:49:04 PM Intrusion.Win.DCOM.exploit 121.63.146.18 TCP 135
9/8/2008 8:49:38 PM Intrusion.Win.MSSQL.worm.Helkern 61.134.56.18 UDP 1434
9/8/2008 9:10:17 PM Intrusion.Win.DCOM.exploit 121.72.241.12 TCP 135
I googled the following about this ansd is all I could find:
10-Mar-2003
10:45 From approx 21:30 last night, there has been an excessive amount
14710823 undesirable traffic on port 445. Yet another windows XP exploit
(worm). Have installed port block in ingress to help protect clients.
http://www.albury.net.au/netstatus/status.cgi?netstatus.2003
TIA


------------------------------------------------------------------------------------------------------------------------------------------------------------------------------