AW: strange .ch scan by 195.141.86.145

From: Pascal C. Kocher (pascal.kocher@netbeat.biz)
Date: 05/28/02


Date: Tue, 28 May 2002 09:03:32 +0200
From: "Pascal C. Kocher" <pascal.kocher@netbeat.biz>
To: "Andreas Wiesmann" <lordandrej@swordlord.org>, <incidents@securityfocus.com>

Hi all

> Hi, I just noticed a strange scan in the web logs of all .ch and .li
> domains. Friends recognized similar scans. So far I dont know what
> the purpose of this scan is... MS collection information?
>
> /www/www.swordlord.ch/access_log:195.141.86.145 - -
> [24/May/2002:20:50:05 +0200] "GET
> http://www.swordlord.ch/hgfserd.aspx HTTP/1.0" 302 289 "-"
> "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR
> 1.0.3705)"

We recorded the same pattern on all of our virtual servers. Preceeding
that pattern, on an irregular timed basis they where trying to get
http://www.w3c.org (as proxy).

Can you also confirm this?

Best regards,
Pascal.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • strange .ch scan by 195.141.86.145
    ... I just noticed a strange scan in the web logs of all .ch and .li ... So far I dont know what ... MS collection information? ... Owner of the IP acording to RIPE is: ...
    (Incidents)
  • Re: [PHP] Objects
    ... dont have time. ... but quite frankly i treat php development much like java ... as a high level language focused on the use ... Or, in my experience with pattern zealots, mis-recognize a problem as ...
    (php.general)
  • list_del corruption with fedora 6 kernels (fc5 was ok)
    ... I dont see a ... pattern, one time it happened after plugging in the USB headphone, another ...
    (Linux-Kernel)
  • Re: Req:looking for a pattern
    ... ok, so i dont ever weld, not that i've not had things that needed welding. ... nzlstar on yahoo msg'r ... I tried to google it but could not find any thing on a pattern. ...
    (rec.crafts.textiles.quilting)
  • Re: Another "your account hsa been disable"
    ... what pattern are you talking about, I will check into the Event ID but when ... I know that the Local admin account cannot be disable so is there anyway ... Try login into domain controller and reset password for account and force ... I dont know what else to try and for worst the local admin password ...
    (microsoft.public.windows.server.general)