 Link LoggerPremium,MVM join:2001-03-29 Calgary, AB kudos:3 Reviews:
·Shaw
| reply to Link Logger
Re: New Worm scanning on 1025, 2745, 3127 and 6129 Just caught another capture on 1024 with a difference MD5 hash then before and the scan pattern was different:
Mar 08, 2004 12:04:26.150 - (TCP) 211.238.194.79 : 2206 >>> 68.144.193.246 : 6129 Mar 08, 2004 12:04:26.130 - (TCP) 211.238.194.79 : 2205 >>> 68.144.193.246 : 445 Mar 08, 2004 12:04:20.121 - (TCP) 211.238.194.79 : 2206 >>> 68.144.193.246 : 6129 Mar 08, 2004 12:04:20.101 - (TCP) 211.238.194.79 : 2205 >>> 68.144.193.246 : 445 Mar 08, 2004 12:04:17.407 - (UDP) 192.168.1.33 : 137 >>> 211.238.194.79 : 137 Mar 08, 2004 12:04:17.287 - (TCP) 211.238.194.79 : 2206 >>> 68.144.193.246 : 6129 Mar 08, 2004 12:04:17.247 - (TCP) 211.238.194.79 : 2205 >>> 68.144.193.246 : 445 Mar 08, 2004 12:04:16.956 - (TCP) 211.238.194.79 : 2194 >>> 192.168.1.38 : 1025
Blake -- Vendor: Firewall Logging Software »www.SonicLogger.com - SonicWall and 3Com »www.LinkLogger.com - Linksys, Netgear and Zyxel |