?
Solved

Find application using port 25 on server 2008R2

Posted on 2016-09-26
5
Medium Priority
?
137 Views
Last Modified: 2016-09-27
I have a server that appears to be randomly sending out traffic over port 25.  To the best of my knowledge this server should not be sending out any traffic over port 25. I have checked with the application vendor and they have confirmed that their software does not use port 25.  This server does run IIS and SQL.  I don't see any configurations in IIS for SMTP or SMTP relay.  I am concerned that there may be malicious activity going on.

I have run wireshark on that server and have verified that the traffic is coming from that server. Each time the event is logged there are only about 3 lines that appear in wireshark. (outbound 25 blocked on edge firewall. Used wireshark to verify traffic originating from the server)

I have run several TCP monitoring applications but the traffic is happening so quick that they don't show what application is opening the port.
The local windows firewall is not running but an edge firewall is running. That is how I see the traffic occurring. I am blocking port 25 from that server on the edge firewall.

I will have to coordinate with the users to be able to turn on the windows firewall as to not interrupt legit traffic.

The destination is 216.35.196.35 and that resolves back to server302.com.  
Whois information on server302 indicates that the administrator is in Bulgaria, but that might be the enom.com administrator
Whois information on the IP points to Savvis / SureSupport LLC
Geolocation data puts the location at Walthan, Massachusetts
The IP address appears to be a DNS server - ns1.server302.com
SureSupport appears to be a hosting provider where server302.com is hosted.

Why would an application be sending port 25 traffic to a name server?
Any ideas on how to find out what application is opening port 25 of this server?
0
Comment
Question by:jpgillivan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 16

Accepted Solution

by:
Todd Nelson earned 2000 total points
ID: 41816930
Take a look at the Windows Sysinternals tools.  There might be something you can download and run on that server to look at suspicious processes like Sysmon and Process Explorer.

https://technet.microsoft.com/en-us/sysinternals

Anything look out of the ordinary in Programs and Features?
0
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 41817880
agree with todd nelson.  sysinternals has a tool called tcpview that can help in such cases.  it's been years since I've been on windows so I can't remember precisely all options, but you should be able to filter results so even though things happen fast, as you say, you should hopefully be able to see what is going on.

if that doesn't work, the only other solution i can think of is writing a small batch file that will call netstat (just dump everything so you're sure you don't miss something) as well as the tasklist command output.  then do an infinite loop running that as it dumps the output to a file.  then watch wireshark to see when the traffic happens again.  once it does you can kill the batch loop, scour the logs for the pid.  this will most likely produce an absolute ton of output though so I'd only do it if tcpview or other sysinternal tools can't help
0
 

Author Closing Comment

by:jpgillivan
ID: 41818317
I tried TCPView but that did not work as the socket open time was too short.  

I was finally able to get the offending program information using ProcessMonitor.  Then I used the "network summary" in the tools menu, found the entry with the url, double clicking on it automatically applied a filter to the output.  Then I was able to see the application and PID.  

Thanks.
2
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 41818343
@jpgillivan

just want to give you kudos for giving such a great and comprehensive closing comment so that people who look at this question will know precisely what to do.  awesome job!
0
 

Author Comment

by:jpgillivan
ID: 41818350
Thanks.  I hate it when an original poster simply says that they fixed it or found the issue.
1

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question