Looks like it's trying to use Runestone[0] (a textbook authoring tool) to get the number of online students but the server url is improperly configured to point at localhost (hence the port scan trigger).
Took a look at Port Authority... it's permissions require access to all data on all websites. Trading one risk for another (bigger) one? It's understandable why such access is needed, but really too bad for privacy.
[0] https://runestoneserverascholer.readthedocs.io/en/latest/ind...