The Norse DarkWolf Labs observed over 706,000 events from 218.77.79.43. The IP had been seen targeting multiple ports and protocols over several months. The number of events gradually increased over the following weeks, with over 70,200 during one week alone. The source port selection is in the 32,000 to 62,000 range for this activity, with the destination having a consistent pattern targeting nine distinct ports (21, 22, 23, 25, 53, 80, 443, 3389, and 8080)”]
Source: https://informationsecuritybuzz.com/news/aggressive-chinese-ip-highlights-attribution-issues/