That supposes that the connection are with legitimate clients, but since the OP referred to "SOME.RANDOM.IP.ADDR", and "connections ... to the outside world", I suspect it was an open proxy.
Maybe.. It depends on how random they are... Still the "destination port is random, source port is my service port" pattern is typical in the scenario I described. -- /kinkie