Re: unusual activity on IP based ports?
"James C Slora" <[email protected]> Wed, 3 Aug 2005 09:07:13 -0400
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
> any chance someone has seen some malware that hashes > the IP its probing to come up with a unique port? Yes, this has been going on widely for at least a year and a half. There are dozens of botnet varieties that do this, and it is a technique that can be built into any tool of course. Randex is one example that often uses the technique you describe. If you look at bot or RAT descriptions and find "opens a random port", this often indicates the open port is some function of the IP address. Thus machines can be probed blindly for the RAT while not having a standard port. So the technique itself does not point to anything specific, but packet captures may shed some more light, especially if you have something answer the probes. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions