[Dshield] Bizarre Activity Spurt...
nelsrob at mts.net
Fri Oct 14 10:24:35 GMT 2005
I'm used to seeing the messenger spam - but I've never seen it arrive in a
burst like this before.
It happened again at just after midnight my time and again at 4:46 AM CDT...
From: list-bounces at lists.dshield.org [mailto:list-bounces at lists.dshield.org]
On Behalf Of Brian Dessent
Sent: October 14, 2005 3:05 AM
To: General DShield Discussion List
Subject: Re: [Dshield] Bizarre Activity Spurt...
Robert Nelson wrote:
> I just had 232 hits on ports 1025 and 1026, all udp, in 42 seconds.
> All had the source port of 7568. All but the first IP listed hit 8
> times, port 1025 then 1026, in a one-second burst each. One IP hit 8
> times, then the next IP hit 8 times... Each 1025-1026 pair was at the
> same time, the next pair from that IP was 12-15 ms later.
Windows messenger spam.
> The following are the source IPs
The source address of these packets was probably spoofed and is meaningless.
> Anybody ever seen anything quite like this?
Frankly, I'd be surprised if it was possible to connect to the internet
these days and *not* receive this.
More information about the list