Phantom connections to 216.37.13.59 & .196

From: Lufo (lufo@iespana.es)
Date: 06/01/02


From: Lufo <lufo@iespana.es>
To: focus-ms@securityfocus.com
Date: 01 Jun 2002 16:51:39 +0200

Hi.
We've noticed that some of the winXP boxes inside our LAN mantain
several connections open to 216.37.13.59 & 216.37.13.196, port 80.

Those servers do not get identified with reverse dns, whois nor
traceroute.

We have thos phantom connections even in boxes without any program
except the OS itself running. Furthermore, netstat says those
connections do not exist...

Does anyone know what are those connections?

Thanks.