Re: unknown outgoing tcp traffic - should I be worried?




Hi all,

My name is Alex Chudnovsky and I am the founder of the Majestic-12
project referenced above.

In the last couple of weeks we were getting reports of fake MJ12bot
user-agent coming from various IPs, the main flag showing that it is a
fake was very old version v1.0.8 of the user-agent just like above.

This is NOT us who do it - we are effectively a victim here as whoever
does this fakes user-agent in the same way spammers fake From: email
address :-(

I am very keen to get to the bottom of exactly what happens - if you
look at our bots page here : 'Majestic-12 : DSearch : MJ12bot'
(http://majestic12.co.uk/bot.php) you will see message about fake bot
and lots of IP addresses from all over the world. I was thinking for
some time that some botnet with compromised PCs were being used to crawl
the web (probably for spamming purposes) using fake user-agents.

Can you try installing Process Explorer from Microsoft:
http://tinyurl.com/289vcz

Do you have any of the firewalls installed like Kerio or ZoneAlarm?
These should have prompted for network traffic coming out asking for
approval.

it gives much greater detail about which processes do what, and it
allows to look at network stats for applications as well. I hope this
will allow to locate exact application that is doing this stuff. It sure
isn't ours (MJ12node.exe) :/


------------------------------------------------------------------------
View this thread: http://www.wirelessforums.org/showthread.php?t=31663
http://www.wirelessforums.org

.



Relevant Pages

  • Re: tru-newz 4 MTRP:
    ... reports the BBC. ... 'Maplestory' is what SCB badly needs to kill its digital characters! ... i had to explain to my father how this was fake ...
    (soc.culture.baltics)
  • Re: Danny Briggs was not the second youngest English spinner to 100 FC wickets
    ... has reported a couple of times that they just take agency reports and ... Jim Swanton must be turning in his grave. ... It would be interesting to know what the fake names are. ... some of the match reports are genuine, even if others have come from an ...
    (uk.sport.cricket)
  • Any Mac utilities for checking for fake flash drives?
    ... My lad has picked up a cheap 32GB flash drive very cheaply - I am wondering whether it is a fake. ... It reports as 32 GB but I know this is easily manipulated - as descibed here..... ...
    (uk.comp.sys.mac)
  • Re: Danny Briggs was not the second youngest English spinner to 100 FC wickets
    ... has reported a couple of times that they just take agency reports and ... Jim Swanton must be turning in his grave. ... It would be interesting to know what the fake names are. ... some of the match reports are genuine, even if others have come from an ...
    (uk.sport.cricket)
  • Re: Russia, Iran, and NASA
    ... Gulf ... >:> How did they fake them on TV? ... Reports vary from 0%-50% with most analysis coming down on the lower ...
    (sci.space.policy)