Distributed MSADC/root.exe scans

From: Chris Adams (chris@improbable.org)
Date: 02/22/02


Date: Thu, 21 Feb 2002 22:44:38 -0700 (MST)
From: "Chris Adams" <chris@improbable.org>
To: <incidents@securityfocus.com>

I've noticed quite a few hosts scanning for a couple of the
vulnerabilities used in the old IIS worms. For example, this afternoon
I've seen scans from just over 500 highly diverse source IPs across 6
class Cs here.
These don't match the normal worm scanning behaviour:
- each IP scans only a small number of hosts - the largest number of
requests I've seen from a single IP is 8 and most scan just one host with
a couple requests- the hosts scanned do not overlap
- the scans are staggered, so we'll get a small batch every 3-10 minutes
- the cycle of scans has repeated for the last few days at what appears to
be long (>1 day) intervals- the IPs aren't scanned contiguously

I have trouble believing someone would go to the trouble of collecting
compromised hosts and then waste them stealthily scanning for
vulnerabilities which even inattentive admins are likely to have patched
and will trigger any halfway decent IDS but a quick google didn't turn up
anything much.
Does anyone know what might be causing this?

Chris

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: threads
    ... Say I'm scanning a class b ... > network (roughly 65K hosts). ... > What are reasonable limits when working with threads in Ruby? ...
    (comp.lang.ruby)
  • Re: threads
    ... Say I'm scanning a class b ... network (roughly 65K hosts). ... What are reasonable limits when working with threads in Ruby? ...
    (comp.lang.ruby)
  • Testing an entire network for (client and server) vulnerabilities
    ... And most of the hosts on ... susceptible to certain vulnerabilities. ... the network contained vulnerable elements (applications, configurations, ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Vulnerability Scanning
    ... After reviewing some scan results and finding a number of false positives from nessus (primarly in XP hosts), ... This is in no way reflecting upon nessus's ability to find vulnerabilities and I truely believe all scanners have these issues. ... false positives and we can't do anything about it? ... If you or your employer does ...
    (Pen-Test)
  • Re: Going from bind9 to djbdns
    ... > My friend, who hosts most of my stuff, is using djbdns. ... BIND 9 is a whole different animal from BIND <=8, ... They do pesky things like find vulnerabilities in his code ...
    (freebsd-questions)