During October 9 through October 11, noticing my system was sometimes unresponsive for seconds at a time, I began to look for other symptoms than a simple over-fragmented hard drive.
On checking the firewall log, I discovered port scans coming from two or three IPs during the last 48 hours.
The IPs are 126.96.36.199 and either 188.8.131.52 (or 20,21) or 184.108.40.206 (or 76-77).
The IP 220.127.116.11 is associated with domain "belfalest.com" and registered with Tierranet Inc.
The IPs 2014.86.118.19 (20-21) and 18.104.22.168 (76-77) are registered with Dreamhost, LLC with no domain owner visible.
Although I am reluctant to raise what is likely to be a false alarm, port scans are hostile behavior and this series of scans is associated with simultaneously depressed system performance.
Any suggestions about what post-scan checks I should put into place before resuming normal operations?
Edited by alphaa10, 13 October 2015 - 07:21 AM.