[Dshield] Cyberkit 2.2 pings.... anyone else getting them?

Very Old News...

On Thu, Oct 09, 2003 at 09:48:34PM -0700, John D. wrote:
> Hi,
> I'm getting shitloads of Cyberkit 2.2 pings hitting our Crunchbox.
> In some cases, about 1 per minute, and they are hitting every box on
> our subnet.
> has anyone else been getting them, and what is the significance of
> these probes. is it some virus probing our network for vulns,  or is
> it something else. 

alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:"ICMP CyberKit 2.2
 ping"; itype: 8; content:"|aa aa aa aa aa aa aa aa|";)

is equivalent to:

alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:"ICMP Nachia
 ping"; itype: 8; content:"|aa aa aa aa aa aa aa aa|";)

Current count (< 24 hours):

One early reference:


