[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-Disclosure] Re: Increased port 135 activity



In article <3F6E8FAC.1020400@xxxxxxxxxxxxxx>,
 Paul Tinsley <pdt@xxxxxxxxxxxxxx> wrote:

> most if not all of the spikes on that graph can be mapped to a 
> worm/virus that was discovered around the same time.


The current port 135 activity appears to be both heavy and more 
narrowly targeted than a recent (typical?) worm activity.

I've seen a few dialups drowned in the traffic (which seems to be scans 
of nearby /16s), while other systems on different parts of the net 
report only the normal levels of MS junk traffic.

I don't know whether the systems you're looking at show similar 
behavior.


Richard

-- 
My mailbox. My property. My personal space. My rules. Deal with it.
                        http://www.river.com/users/share/cluetrain/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html