Richard M
18-08-2003, 17:22
OK - that is resolved (and is a fix for ZA owners) but I have noticed a worrying sharp increase in pings to my IP from NTL IPs.
It's like the worm, except that it's more frequent.
Check this out:
FWIN,2003/08/18,17:09:20 +1:00 GMT,81.99.28.85:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:09:28 +1:00 GMT,81.98.255.23:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:09:44 +1:00 GMT,200.77.111.136:4977,*.*.*.*:2318,TCP (flags:S)
FWIN,2003/08/18,17:10:12 +1:00 GMT,81.104.8.10:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:10:16 +1:00 GMT,81.101.161.22:3564,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:10:22 +1:00 GMT,172.196.97.59:2279,*.*.*.*:4662,TCP (flags:S)
FWIN,2003/08/18,17:10:40 +1:00 GMT,81.101.29.163:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:10:42 +1:00 GMT,81.101.113.197:3303,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:10:46 +1:00 GMT,81.101.22.102:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:11:44 +1:00 GMT,81.100.194.15:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:12:12 +1:00 GMT,81.101.29.171:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:12:14 +1:00 GMT,81.101.213.19:1911,*.*.*.*:445,TCP (flags:S)
FWIN,2003/08/18,17:12:14 +1:00 GMT,81.101.43.123:2277,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:12:16 +1:00 GMT,81.101.209.133:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:12:24 +1:00 GMT,81.101.244.6:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:12:34 +1:00 GMT,81.101.148.148:1623,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:12:50 +1:00 GMT,81.99.188.193:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:13:00 +1:00 GMT,81.98.39.69:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:13:04 +1:00 GMT,81.98.255.135:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:13:24 +1:00 GMT,81.104.239.91:0,*.*.*.*:0,ICMP (type:8/subtype:0)
PE,2003/08/18,17:13:46 +1:00 GMT,Generic Host Process for Win32 Services,194.168.4.100:53,N/A
FWIN,2003/08/18,17:13:46 +1:00 GMT,81.104.160.116:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:14:02 +1:00 GMT,81.101.152.185:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:14:06 +1:00 GMT,81.101.127.52:4645,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:14:18 +1:00 GMT,81.103.247.93:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:14:20 +1:00 GMT,81.101.255.129:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:14:32 +1:00 GMT,81.101.54.239:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:14:42 +1:00 GMT,81.101.161.52:2886,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:14:58 +1:00 GMT,81.101.8.57:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:15:16 +1:00 GMT,81.100.148.122:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:15:58 +1:00 GMT,81.101.148.148:4473,*.*.*.*:139,TCP (flags:S)
FWIN,2003/08/18,17:16:02 +1:00 GMT,81.101.159.164:1465,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:16:10 +1:00 GMT,81.101.88.194:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:16:32 +1:00 GMT,81.103.112.102:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:16:38 +1:00 GMT,81.102.45.5:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:16:44 +1:00 GMT,81.103.146.203:4044,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:17:22 +1:00 GMT,81.98.107.7:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:17:34 +1:00 GMT,81.101.126.208:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:17:42 +1:00 GMT,81.102.224.53:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:17:54 +1:00 GMT,81.101.20.118:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:18:06 +1:00 GMT,81.101.4.23:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:18:24 +1:00 GMT,81.101.53.131:3942,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:18:46 +1:00 GMT,81.98.173.183:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:18:58 +1:00 GMT,81.101.255.175:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:19:24 +1:00 GMT,81.101.62.20:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:20:08 +1:00 GMT,81.101.4.65:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:20:10 +1:00 GMT,81.101.183.8:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:20:20 +1:00 GMT,81.103.194.193:0,*.*.*.*:0,ICMP (type:8/subtype:0)
FWIN,2003/08/18,17:20:22 +1:00 GMT,81.100.237.102:4861,*.*.*.*:135,TCP (flags:S)
FWIN,2003/08/18,17:20:30 +1:00 GMT,81.99.146.23:0,*.*.*.*:0,ICMP (type:8/subtype:0)
:eek:
Upon further investigation, it appears that there is a new worm about already: http://isc.sans.org/diary.html?date=2003-08-18
:erm:
vBulletin® v3.8.11, Copyright ©2000-2024, vBulletin Solutions Inc.