re: TCP 1025 scanning worm?

From: H C (keydet89@yahoo.com)
Date: 07/18/02


Date: Thu, 18 Jul 2002 11:36:35 -0700 (PDT)
From: H C <keydet89@yahoo.com>
To: incidents@securityfocus.com


> The sources are all Windows boxes listening on TCP
port 1025.

Not surprising at all. MS has documentation that
states that the ports from 1025-1030 are used by RPC.

Have you checked your own machine w/ fport? I've got
ports open in that range on my system right now, but
they're all used by MS processes.

> The ramp up in volume from widely separated source
IPs looks wormy.

How so? The log extract you provided doesn't show any
data...it looks as if the initial SYN packet was
denied. This could easily be a port scanner.

__________________________________________________
Do You Yahoo!?
Yahoo! Autos - Get free new car price quotes
http://autos.yahoo.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Worm1800.exe on UnderNet?
    ... :!Notice!: A Recent Port Scan on your Computer reveals that Port 1800 ... For more information on this free incident handling, management ... and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: Port 6635
    ... >We received a very fast scan for port 6635 last night. ... >For more information on this free incident handling, management ... >and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: increased attacks on port 2599
    ... All I see are SYN packets...where are the 'attacks' ... > attacks @ port 2599... ... For more information on this free incident handling, ... and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: Increased connects to Port 1433
    ... Increased connects to Port 1433 ... For more information on this free incident handling, management ... and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: Mysterious "Support" account created on Win2k server
    ... port 445 worm/virus/Trojans are the ones spread via SMB over TCP, port 445, ... Mysterious "Support" account created on Win2k server ... > For more information on this free incident handling, ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)