Re: Strange echo requests from 127.0.0.1 apparently to root nameservers
"Roland" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Terje, There is a shareware utility developed by Foundstone, Inc. http://www.foundstone.com called fport.exe which is able link the port and pid in one command line program. See output below c:\fport Pid Process Port Proto Path 392 svchost -> 135 TCP C:\WINNT\system32\svchost.exe 8 System -> 139 TCP 8 System -> 445 TCP 508 MSTask -> 1025 TCP C:\WINNT\system32\MSTask.exe 392 svchost -> 135 UDP C:\WINNT\system32\svchost.exe 8 System -> 137 UDP 8 System -> 138 UDP 8 System -> 445 UDP 224 lsass -> 500 UDP C:\WINNT\system32\lsass.exe 212 services -> 1026 UDP C:\WINNT\system32\services.exe In addition there is another utility called handle developed by Sysinternals @ http://www.sysinternals.com/ntw2k/freeware/handle.shtml. This utility links process IDs to ports and program names, Terje Trane wrote: >I tried to troubleshoot a PC that all of a sudden would connect but not >route traffic to a remote site by VPN and started Ethereal to see if I could >see where the packets were going. > >To my surprise I can see a dozen ICMP echo request packets per second sent >from 127.0.0.1. Every other is to my internal DNS-servers, and the rest >(except for a few) to *.root-servers.net and *.gtld-servers.net. > >My thought was that this is malware scanning or trying a DoS on the DNS, >though AV is up to date and running. However, the firewall technician says >he cannot see this traffic at the firewall. I tried using tcpdump on an >other machine on the same hub and cannot see this traffic, so I guess it >must be local? > >By looking at the MAC-addresses i see that all packets are from >08:00:2b:00:dc:dc which is not the MAC address of the local PC and completly >unknown to me, and they are sent to 08:00:2b:00:01:02 which is also unknown. >08:00:2b is the vendor code for DEC and we have no DEC equipment here. > >I tried killing the processes I don't know on this PC, but not all will die. >Is there any way in Windows I can see what process is generating what TCP/IP >traffic? > >And most important: What can this be? > > >_______________________________________________ >Intrusions mailing list >[email protected] >http://www.dshield.org/mailman/listinfo/intrusions > > > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions