Strange echo requests from 127.0.0.1 apparently to root nameservers
"Terje Trane" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
I tried to troubleshoot a PC that all of a sudden would connect but not route traffic to a remote site by VPN and started Ethereal to see if I could see where the packets were going. To my surprise I can see a dozen ICMP echo request packets per second sent from 127.0.0.1. Every other is to my internal DNS-servers, and the rest (except for a few) to *.root-servers.net and *.gtld-servers.net. My thought was that this is malware scanning or trying a DoS on the DNS, though AV is up to date and running. However, the firewall technician says he cannot see this traffic at the firewall. I tried using tcpdump on an other machine on the same hub and cannot see this traffic, so I guess it must be local? By looking at the MAC-addresses i see that all packets are from 08:00:2b:00:dc:dc which is not the MAC address of the local PC and completly unknown to me, and they are sent to 08:00:2b:00:01:02 which is also unknown. 08:00:2b is the vendor code for DEC and we have no DEC equipment here. I tried killing the processes I don't know on this PC, but not all will die. Is there any way in Windows I can see what process is generating what TCP/IP traffic? And most important: What can this be? _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions