[Dshield] Blitznet?

Tim Kroeger tkroeger at comcast.net
Tue Sep 9 22:53:45 GMT 2003


14:36 03Sep09 from 123.456.9.178:23 123.456.13.185:3609 tcp BLITZNET     
14:36 03Sep09 from 123.456.9.178:23 123.456.13.150:3609 tcp BLITZNET     
14:36 03Sep09 from 123.456.9.178:23 123.456.13.122:3609 tcp BLITZNET     
14:36 03Sep09 from 123.456.9.178:23 123.456.13.102:3609 tcp BLITZNET     
14:36 03Sep09 from 123.456.9.178:23 123.456.13.72:3609 tcp BLITZNET     
14:36 03Sep09 from 123.456.9.178:23 123.456.13.48:3609 tcp BLITZNET     
14:36 03Sep09 from 123.456.9.178:23 123.456.13.33:3609 tcp BLITZNET     
14:35 03Sep09 from 123.456.9.178:23 123.456.4.199:3609 tcp BLITZNET     
14:35 03Sep09 from 123.456.9.178:23 123.456.4.111:3609 tcp BLITZNET     
14:35 03Sep09 from 123.456.9.178:23 123.456.4.49:3609 tcp BLITZNET     
14:35 03Sep09 from 123.456.9.178:23 123.456.4.27:3609 tcp BLITZNET    


This is a dial-up user who was also infected with Nachi.  We were logging this 
at the same time we were seeing Nachi from the same user.

I have found very little on Blitznet.  Is this Blitznet?  


Thanks,
Tim  



More information about the list mailing list