During October 9 through October 11, noticing my system was sometimes unresponsive for seconds at a time, I began to look for other symptoms than a simple over-fragmented hard drive.
On checking the firewall log, I discovered port scans coming from two or three IPs during the last 48 hours.
The IPs are 220.127.116.11 and either 18.104.22.168 (or 20,21) or 22.214.171.124 (or 76-77).
The IP 126.96.36.199 is associated with domain "belfalest.com" and registered with Tierranet Inc.
The IPs 2014.86.118.19 (20-21) and 188.8.131.52 (76-77) are registered with Dreamhost, LLC with no domain owner visible.
Although I am reluctant to raise what is likely to be a false alarm, port scans are hostile behavior and this series of scans is associated with simultaneously depressed system performance.
Any suggestions about what post-scan checks I should put into place before resuming normal operations?
Edited by alphaa10, 13 October 2015 - 07:21 AM.