HIGH: Accessible SMB Report

DESCRIPTION LAST UPDATED: 2023-12-27

DEFAULT SEVERITY LEVEL: HIGH

This report identifies hosts that have an SMB instance running on port 445/TCP that are accessible on the Internet.

This service should not be exposed to the Internet.

You can track SMB exposure on our Dashboard.

Severity levels are described here.

For more information on our scanning efforts, check out our Internet scanning summary page..

This report has an IPv4 and IPv6 version.

Filename(s): scan_smb, scan6_smb

Fields

  • timestamp
    Time that the IP was probed in UTC+0
  • severity
    Severity level
  • ip
    The IP address of the device in question
  • protocol
    Protocol that the response came on (always TCP)
  • port
    Port that the response came from (445/TCP)
  • hostname
    Reverse DNS name of the device in question
  • tag
    Will always be smb
  • asn
    ASN of where the device in question resides
  • geo
    Country where the device in question resides
  • region
    State / Province / Administrative region where the device in question resides
  • city
    City in which the device in question resides
  • naics
    North American Industry Classification System Code
  • hostname_source
    Hostname source
  • arch
    If an smb-implant is present, indicates if the system architecture is 32-bit (x86) or 64-bit (x64)
  • key
    If an smb-implant is present, indicates the crypto key
  • smb_major_number
    SMB major version number
  • smb_minor_number
    SMB minor version number
  • smb_revision
    SMB revision number
  • smb_version_string
    SMB version string
  • sector
    Sector the IP belongs to

Sample

"timestamp","severity","ip","protocol","port","hostname","tag","asn","geo","region","city","naics","hostname_source","arch","key","smb_major_number","smb_minor_number","smb_revision","smb_version_string","sector"
"2010-02-10 00:00:00",high,192.168.0.1,tcp,445,node01.example.com,smb,64512,ZZ,Region,City,0,ptr,,,2,1,0,"SMB 2.1","Professional, Scientific, and Technical Services"
"2010-02-10 00:00:01",high,192.168.0.2,tcp,445,node02.example.com,smb,64512,ZZ,Region,City,0,,,,2,1,0,"SMB 2.1",
"2010-02-10 00:00:02",high,192.168.0.3,tcp,445,node03.example.com,smb,64512,ZZ,Region,City,0,ptr,,,2,1,0,"SMB 2.1","Communications, Service Provider, and Hosting Service"

Our 130 Report Types