Security Incidents mailing list archives

Which worm is it?


From: Joe McAlerney <joey () SILICONDEFENSE COM>
Date: Fri, 22 Sep 2000 17:54:37 -0700

[somewhat of a follow up to the thread "new scanner tool or blind
luck?"]

Hello,

We have been getting scanned by hosts in close class B net's to ours
(one below, one above, two above, etc.)  I'm sure many others are seeing
the same thing.  The destination port is always 139 (four packets per
destination host), and the source port is always above 1024 and
incrementing between hosts.  What's more fun is that our neighbors like
to come back.  We're starting to see repeats of the same scans.

I would like to know what worm this is, and somewhere I can point these
poor souls to, so that they can rid their systems of this annoying
menace.  I've been following the discussions about QAZ and netw0rk.vbs,
but (correct me if I am wrong) there doesn't seem to be any solid
conclusions.  From what I read, QAZ defaults to port 7597 so either it
mutated, or it's not our bug.  netw0rk.vbs defaults to source port 139,
so again.. close but no cigar.

I bet you have been waiting for that question mark, so here it comes...
Has anyone nailed this one down?  Fortunately we are not infected by the
worm, but unfortunately that makes it harder to analyze.

Thank you,

-Joe M.


Current thread: