Community Forum

DoS attack: TCP- or UDP-based Port Scan] from 75.75.76.76, port 53

Highlighted
New Poster

DoS attack: TCP- or UDP-based Port Scan] from 75.75.76.76, port 53

internet is getting disconnected frequently and it is random.. this is what i see in event logs

 

 

[DoS attack: TCP- or UDP-based Port Scan] from 75.75.76.76, port 531Thu Nov 19 13:41:49 2020  
[DoS attack: TCP- or UDP-based Port Scan] from 75.75.75.75, port 531Thu Nov 19 13:41:48 2020  
[Internet connected] IP address: 1Thu Nov 19 13:41:44 2020  
[Time synchronized with ToD server]1Thu Nov 19 13:41:37 2020  
[admin login] from source 192.168.0.101Thu Nov 19 13:40:15 2020  
[admin login failure] from source 192.168.0.101Thu Nov 19 13:40:13 2020  
[Time synchronized with ToD server]1Thu Nov 19 13:38:43 2020  
[Internet disconnected]1Thu Nov 19 13:37:55 2020  
[DoS attack: TCP- or UDP-based Port Scan] from 75.75.76.76, port 531Thu Nov 19 13:31:43 2020  
[DoS attack: TCP- or UDP-based Port Scan] from 75.75.75.75, port 531Thu Nov 19 13:31:39 2020  
Highlighted
Expert

Re: DoS attack: TCP- or UDP-based Port Scan] from 75.75.76.76, port 53


@Router-admshaik wrote:

internet is getting disconnected frequently and it is random.. this is what i see in event logs

 

 

[DoS attack: TCP- or UDP-based Port Scan] from 75.75.76.76, port 531Thu Nov 19 13:41:49 2020  
[DoS attack: TCP- or UDP-based Port Scan] from 75.75.75.75, port 531Thu Nov 19 13:41:48 2020  
[Internet connected] IP address: 1Thu Nov 19 13:41:44 2020  
[Time synchronized with ToD server]1Thu Nov 19 13:41:37 2020  
[admin login] from source 192.168.0.101Thu Nov 19 13:40:15 2020  
[admin login failure] from source 192.168.0.101Thu Nov 19 13:40:13 2020  
[Time synchronized with ToD server]1Thu Nov 19 13:38:43 2020  
[Internet disconnected]1Thu Nov 19 13:37:55 2020  
[DoS attack: TCP- or UDP-based Port Scan] from 75.75.76.76, port 531Thu Nov 19 13:31:43 2020  
[DoS attack: TCP- or UDP-based Port Scan] from 75.75.75.75, port 531Thu Nov 19 13:31:39 2020  


75.75.75.75 and 75.75.76.76 are the Comcast DNS servers, and Port 53 is a legitimate DNS port.  Your security software is apparently flagging these as malware when they're not. 


I am not a Comcast Employee.
I am a Customer Expert volunteering my time to help other customers here in the Forums.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Mark the post as Best Answer!