logo

TSUBAME Report Overflow (Jan-Mar 2025)

ID: 91662a17-a703-5654-adc9-bed0cd68b005

STIX ID: report--91662a17-a703-5654-adc9-bed0cd68b005

Feed Name: JPCERT Blog

Threat Score
60/100

Date Published: 2025-07-08

Date Updated: 2026-04-19

Author: 鹿野 恵祐 (Keisuke Shikano)

...
...

This TSUBAME monitoring report (Jan–Mar 2025) summarizes FY2024 trends where Mirai-like scanning dominated traffic to port 23/TCP with notable spikes in May 2024, Sep–Dec 2024, and Feb–Mar 2025; affected devices included routers (TP-Link, ASUS), security cameras, DVRs, and NAS. TSUBAME sensors observed associated scans to other ports and DDoS reflection traffic, compared top scanned ports across sensors (23, 8728, 22, 8080, 80, ICMP, 6379), and recommends firmware updates, secure configuration, port hardening and use of tools like SHODAN and port scans to mitigate botnet infection and DDoS risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.