Re: Ports 33435 to 33438, 2082 over past forty days
Timothy Chase <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Ronaldo, You are probably right about the UDP traffic on ports 33435-8. Just seemed odd that it had gone up like that (a factor of 2), but fluctuations are to be expected. The TCP on 2082 went up a great deal further -- by over a factor of 7 in the same amount of time. Haven't found any other instances of the association of UDP traffic on ports 33435-8 with the bot activity on TCP 2745 and 2082, but I have found plenty of UDP traffic on those ports. Moreover, looking more closely at the packets I received on TCP 2745 and 2082, it looks more like a new login has been created, but not a login intended to replace the original login associated with the Bagle backdoor -- and I actually haven't seen much of that activity. (TCP on 2082 is normally associated with a website control panel -- e.g., phpMyAdmin through CPanel.) What has been more interesting has been the variety in worm activity on tcp 3127 since MyDoom's return -- things I haven't seen before. And I am see some new infections -- just on the Comcast network alone, it looks like the number of IP addresses which are infected have about doubled, although much of that will no doubt be temporary. (Would be nice to hasten the demise of those infections, if possible...) Take care, Tim On Mon, 9 Aug 2004 15:13:45 -0300 (BRST), Ronaldo C Vasconcellos <[email protected]> wrote: > UDP? It may be just traceroute: > > Samspade.org - UDP traffic on ports 33434 - 33523 > http://www.samspade.org/d/faq/ > > Best regards, > > --- > Ronaldo C Vasconcellos CAIS/RNP > ronaldo @ cais.rnp.br Brazilian Research Network CSIRT > http://www.rnp.br/en/cais > > > > On Sat, 31 Jul 2004, Timothy Chase wrote: > > > Summary: > > > > Over the past forty days, http://isc.incidents.org is showing > > increased activity on ports 33435-8 (going from 3000 to 7000 requests) > > and 2082 (less than 1000 to over 7000 requests), and is currently > > showing over 500 sources. Ports 1025 and 2745 appear to be involved, > > but are not showing the same dramatic change in activity. > > > > ---- > > > > Looking over my firewall log, I noticed some suspicious activity -- > > attempted connections from a machine on ports 33435 through 33438. > > Going to: > > > > http://isc.incidents.org > > > > I found that activity (reports and targets) has been climbing over the > > past 40 days, with a low peak below 3000 around July 4th, and the most > > recent peak at just below 7000. Moreover, the activity on all four > > ports has been very similiar, producing almost identical graphs. I > > have as of yet to capture packets on those ports, but looking at one > > of the ip addresses which showed up in the firewall log (a home cable > > user, it appears), I saw activity on two other ports: > > > > 2745, 2082. > > > > Over the past forty days, port 2082 has been showing increasing > > activity similiar to 33435-33438, going from under 1000 records from > > June 22 to July 12, to a most recent peak on July 28th of just over > > 7000 at ISC. The firewall also shows activity on 1025 from the same > > ip address. > > > > So it appears we have something growing out there, showing a strong > > pattern over the past 40 days, particularly on ports 3345-8 and 2082, > > although it is also using the more common ports of 1025 and 2745. The > > tcp packet captures I have so far are only from 2745 and 2082, but I > > will be trying to get some from 33435-8 in the days ahead. > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions