Posted January 18, 201213 yr While reviewing my firewall logs, I noted that something called Gemplus Cryptographic Service Provider recently started hammering at my firewall, trying to access a LOT of different IP addresses, all using TCP/IP destination ports 53, 443 and 5050. The origination ports are all over the map but don't seem to appear more than once. This GCSP appears to be something related to secure card readers, which I haven't loaded and don't use. Does anyone have any info on A) what this is, B) where it might have originated, C) and what it's trying to accomplish? My intuition tells me that it's malware, yet all of my malware scans come up empty. I'm really curious about this thing. My system says "no such file" when I go looking for "oiu0.1496646520172633.exe", and a Tracert to 216.244.77.251 results in 1 1 ms
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.