Semi-Troubling Traffic, possible cracking tool running as a Trojan?
Chris Burton <[email protected]> Fri, 10 Oct 2003 19:19:48 -0700 (PDT)
| Newsgroups | gmane.comp.security.incident-handling |
|---|---|
| Message-ID | <[email protected]> |
Everyone,
I have had some interesting traffic on my network
recently. We have multiple sites with an IDS
monitoring the internal network. We see a lot of SMB
Authentication Failures against the PDC from a
specific workstation. Somewhere in the neighborhood
of 3000 attempts an hour. I think that this is simply
because the PDC is busy with other things and not
process the requests fast enough. One night, we saw
this number reach 25000 attempts an hour, from 6:00 pm
until 9:00 am when the network became loaded again and
then the machine was rebooted and the traffic stopped.
We saw the traffic again from a different machine on
the same subnet, and then on a completely different
machine 2000 miles away. And then again on the east
coast (the first two were in the Mid-West). These are
all the same image, but process listings show that no
processes of interest are running (WordPerfect 9.0
being the only commonality)
We were able to turn on a packet capture, and
also retrieve a process listing while the traffic was
occurring. The packet captured exactly what we
thought (SMB Failures). We grabbed the logs from the
PDC and the workstation which showed nothing out of
the ordinary. We are thinking now that we need to
turn on Object and Process Auditting (Very Intensive),
to see what happens.
So the question is, have you seen this before?
Where do I go from here is the Object and Process
Auditing doesn't have anything interesting?
Can't take down any boxes, can fly out to the
sites.
Regards,
Chris
__________________________________
Do you Yahoo!?
The New Yahoo! Shopping - with improved product search
http://shopping.yahoo.com