Security Incidents mailing list archives
Re: Unusual volume: UDP:137 probes
From: Christopher Albert <albert () DMS UMontreal CA>
Date: Mon, 30 Sep 2002 16:45:39 -0400
Emeric Miszti wrote:
On Monday 30 Sep 2002 9:33 am, Mark Forsyth wrote:On Monday, September 30, 2002 9:02 AM, John Sage [SMTP:jsage () finchhaven com] wrote:This has received some mention on the UNISOG list and elsewhere, but not here. Some people have been seeing unusually high volumes of UDP:137 probes since about 09/27/02 late, or early 09/28/02.
<snip>
Been seeing exactly the same spike with same patterns. Up from 40 odd scans on 28/9/2002 to 495 already today.Incidents.org have picked this up at the Internet Storm Center http://isc.incidents.org/port_details.html?port=137 No explanations or reasons been given by anyone yet.
This might be W32/Bubbear@MM , which spreads by SMTP and network shares:* * http://vil.nai.com/vil/content/v_99728.htm http://www.sophos.com/virusinfo/analyses/w32bugbeara.html Chris --------------------------------------------------------------------Christopher Albert Responsable des services informatiques
Departement de mathematiques et de statistiqueUniversite de Montreal
bureau 6188, Pavillon Andre-AisenstadtTel: (514) 343-2281 Fax: (514) 343-5700 --------------------------------------------------------------------
---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service.For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- RE: Unusual volume: UDP:137 probes Bamm (Robert) Visscher (Sep 30)
- <Possible follow-ups>
- Re: Unusual volume: UDP:137 probes Nick FitzGerald (Sep 30)
- RE: Unusual volume: UDP:137 probes Mark Forsyth (Sep 30)
- RE: Unusual volume: UDP:137 probes Joseph R. Gruber (Sep 30)
- Re: Unusual volume: UDP:137 probes Hugo van der Kooij (Sep 30)
- SV: Unusual volume: UDP:137 probes Peter Kruse (Oct 01)
- Re: Unusual volume: UDP:137 probes Christopher Albert (Sep 30)
- RE: Unusual volume: UDP:137 probes Richard . Grant (Oct 01)
- RE: Unusual volume: UDP:137 probes Nick FitzGerald (Oct 03)
- Re: Unusual volume: UDP:137 probes Alain Fauconnet (Oct 04)
- Re: Unusual volume: UDP:137 probes Matt Power (Oct 05)
- RE: Unusual volume: UDP:137 probes Nick FitzGerald (Oct 03)
- RE: Unusual volume: UDP:137 probes Scott, Michael R. (Oct 01)
- Re: Unusual volume: UDP:137 probes Axel Pettinger (Oct 01)
- Re: Unusual volume: UDP:137 probes James Sneeringer (Oct 01)
- maybe a simple problem Andrew Fison (Oct 02)
- Re: maybe a simple problem Igor D. Spivak (Oct 02)
- RE: maybe a simple problem Greg Reber (Oct 03)
- Re: Unusual volume: UDP:137 probes James Sneeringer (Oct 01)