Page 1 of 1

Lots of connection attempts from IPs on abuse list

Posted: Thu Feb 25, 2021 8:02 pm
by lawsangel
I seem to get quite a lot of connection attempts every single day for IP's which mostly seem to be on some sort of reported spam / abuse list.

For example:
2021-02-25 15:27:50.186 On the TCP Listener (Port 5555), a Client (IP address, Host name "", Port number 65438) has connected.
2021-02-25 15:27:50.186 For the client (IP address:, host name: "", port number: 65438), connection "CID-32" has been created.
2021-02-25 15:27:50.186 Connection "CID-32" has been terminated.
2021-02-25 15:27:50.186 The connection with the client (IP address, Port number 65438) has been disconnected.

Is this normal?

Re: Lots of connection attempts from IPs on abuse list

Posted: Sat Feb 27, 2021 10:10 am
by nobody12
I think this i pretty normal,
The IPs on those lists are most likely on the list because their are part of some kind of botnet which tries to find and penetrate loopholes in routers or webservers.
If you run a system connected to the internet and have services available on known ports like 80,443,25,8080 etc. you have to live with that.
I run a small smtp hub. Somtimes I had about 5.000+ attempts to break in in a day.

Re: Lots of connection attempts from IPs on abuse list

Posted: Mon Mar 01, 2021 1:01 am
by lawsangel
Ok, that makes sense.
Just wasnt sure if these were direct attacks on SoftEther, or just random attempts to connect to the port.