worm information

Jack McCarthy nanog at jackmccarthy.com
Sat Apr 10 18:36:37 UTC 2004


Agobot scanning...

Take a look at these links:

http://isc.sans.org/diary.php?date=2004-04-05
http://isc.sans.org/diary.php?date=2004-04-01
http://isc.sans.org/diary.php?date=2004-04-09

Also, take a read through the "New Worm???" thread at:
http://www.dshield.org/pipermail/intrusions/2004-April/thread.php



-Jack





--- "Christopher J. Wolff" <chris at bblabs.com> wrote:
> 
> Hello,
> 
> Over the last few days I've seen a number of hosts attempt to initiate TCP
> connections to the following ports in sequence.
> 
> 80
> 139
> 445
> 6129
> 3127
> 1025
> 135
> 2745
> ...repeat.
> 
> At this moment I haven't seen a correlation between this activity and the
> port exploitation list on CERT.  Any insight would be appreciated, thank
> you.
> 
> Regards,
> Christopher J. Wolff, VP CIO
> Broadband Laboratories, Inc.
> http://www.bblabs.com
> 
> 
> 
> 
> 




More information about the NANOG mailing list