1. Open conn.log. Nearly all destination ports get a REJ/RST (closed) from one source IP in a tight time window — a classic SYN scan. Why: a scanner touches many ports fast; closed ports reset, open ones complete the handshake.
2. Exactly one port shows SF (established) with a service banner. That banner line contains THM{...}.
3. Filter the log for the SF/established row (in-page filter box) to read it.
Lesson: scan detection = many rejects from one source + the few that succeed.