Hacker News new | ask | show | jobs
by psykovsky 4330 days ago
A quick google search seems to indicate that 21320 is a port commonly used to setup a proxy after an infection. It's probably the attacker trying to use the honeypot as a proxy after a "successful" infection of the machine.