Hello davex268,
Thank you for your question.
I'm afraid you can not identify the specific identity of the sender
from this information.
First, the 4089 is a port number. I'm assuming you found that
information from a firewall log file and it is most likely the port
used to send the transmission to you.
Iana.org reports this port as follows:
http://www.iana.org/assignments/port-numbers
# 4043-4095 Unassigned
So this was a randomly chosen available port to transmit from the
sending computer.
The IP address you provided is one of AOL's:
OrgName: America Online
OrgID: AOL
Address: 8619 Westwood Center Drive
Address: Suite 200
City: Vienna
StateProv: VA
PostalCode: 22182
Country: US
NetRange: 172.128.0.0 - 172.191.255.255
CIDR: 172.128.0.0/10
NetName: AOL-172BLK
NetHandle: NET-172-128-0-0-1
Parent: NET-172-0-0-0-0
NetType: Direct Allocation
NameServer: DAHA-01.NS.AOL.COM
NameServer: DAHA-02.NS.AOL.COM
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2000-03-24
Updated: 2002-08-09
TechHandle: AOL-NOC-ARIN
TechName: America Online, Inc.
TechPhone: +1-703-265-4670
TechEmail: domains@aol.net
OrgAbuseHandle: AOL382-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-703-265-4670
OrgAbuseEmail: abuse@aol.net
OrgNOCHandle: AOL236-ARIN
OrgNOCName: NOC
OrgNOCPhone: +1-703-265-4670
OrgNOCEmail: noc@aol.net
OrgTechHandle: AOL-NOC-ARIN
OrgTechName: America Online, Inc.
OrgTechPhone: +1-703-265-4670
OrgTechEmail: domains@aol.net
# ARIN WHOIS database, last updated 2003-05-01 20:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
If you are sure this was the IP address that has sent you this Trojan,
you might email abuse@aol.net with all the details. USUALLY, they will
require copies of your firewall logs to verify that you are being
attacked by one of their users. You will have a better chance of them
looking into this if this IP address has been active more than once in
trying to access your computer. They will need to know the times of
attempted attacks from your logs to identify the attacker if the IP
address is dynamic and not permanently assigned to a specific user.
And, if by chance you are not using a firewall, I would highly
recommend the free version of Zone Alarm available at www.zonelabs.com
I trust my research has provided you with useful information. If a
link above should fail to work or anything require further explanation
or research, please do post a Request for Clarification prior to
rating the answer and closing the question and I will be pleased to
assist further.
Regards,
-=clouseau=- |