North American Network Operators Group Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical Re: worm information
Agobot scanning... Take a look at these links: http://isc.sans.org/diary.php?date=2004-04-05 http://isc.sans.org/diary.php?date=2004-04-01 http://isc.sans.org/diary.php?date=2004-04-09 Also, take a read through the "New Worm???" thread at: http://www.dshield.org/pipermail/intrusions/2004-April/thread.php -Jack --- "Christopher J. Wolff" <[email protected]> wrote: > > Hello, > > Over the last few days I've seen a number of hosts attempt to initiate TCP > connections to the following ports in sequence. > > 80 > 139 > 445 > 6129 > 3127 > 1025 > 135 > 2745 > ...repeat. > > At this moment I haven't seen a correlation between this activity and the > port exploitation list on CERT. Any insight would be appreciated, thank > you. > > Regards, > Christopher J. Wolff, VP CIO > Broadband Laboratories, Inc. > http://www.bblabs.com > > > > >
|