Security Incidents mailing list archives
Which worm is it?
From: Joe McAlerney <joey () SILICONDEFENSE COM>
Date: Fri, 22 Sep 2000 17:54:37 -0700
[somewhat of a follow up to the thread "new scanner tool or blind luck?"] Hello, We have been getting scanned by hosts in close class B net's to ours (one below, one above, two above, etc.) I'm sure many others are seeing the same thing. The destination port is always 139 (four packets per destination host), and the source port is always above 1024 and incrementing between hosts. What's more fun is that our neighbors like to come back. We're starting to see repeats of the same scans. I would like to know what worm this is, and somewhere I can point these poor souls to, so that they can rid their systems of this annoying menace. I've been following the discussions about QAZ and netw0rk.vbs, but (correct me if I am wrong) there doesn't seem to be any solid conclusions. From what I read, QAZ defaults to port 7597 so either it mutated, or it's not our bug. netw0rk.vbs defaults to source port 139, so again.. close but no cigar. I bet you have been waiting for that question mark, so here it comes... Has anyone nailed this one down? Fortunately we are not infected by the worm, but unfortunately that makes it harder to analyze. Thank you, -Joe M.
Current thread:
- Which worm is it? Joe McAlerney (Sep 24)
- Re: Which worm is it? Ryan Russell (Sep 25)
