Currently I am having an issue with a host on the private MPLS network who is attempting to setup connections to random hosts on port 445. This host is using a spoofed IP address to do the work, and it doesn't seem that he is sequentially moving through the IP ranges. I have engaged our service provider to see if they can help track the host over the MPLS.
So far, I have not been able to find a reliable way to find this host. I have a network tool spanning our main MPLS pipe into our Data Center, and I can see that some hosts are attempting to reply, but the spoofed IP is not a routable address on our network. Therefore this host is not replicating itself, but instead just cause alarms to go off and the increase in resources to move these packets through.
Anyone have any ideas on how to track this host to a certain area?