Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Port 6667 & 10.0.1.128/1.1.1.1/1.3.3.7

 
Thread Tools Search this Thread
Old 09-18-2003, 04:32 PM   #1
Default Port 6667 & 10.0.1.128/1.1.1.1/1.3.3.7


Hello,

I'm seeing a lot of traffic trying to leave my firewall destined for
port 6667 at the IPs 10.0.1.128, 10.10.10.10, 1.1.1.1 and 1.3.3.7
(sounds like l337/elite to me .

Yes - I know the 10.x.x.x traffic isn't going too far.... RFC1918, etc,
etc.

Various Google searches and searches on the various A/V sites haven't
turned up a definite answer - just more questions about the same thing.

Can anyone clue me in to the exact trojan/worm/virus this may be and/or
if they're seeing the same kind of traffic.

Any insight is appreciated....

Thanks.

B



ex-Zephion
  Reply With Quote
Old 09-18-2003, 08:34 PM   #2
Damjan
 
Posts: n/a
Default Re: Port 6667 & 10.0.1.128/1.1.1.1/1.3.3.7
> Hello,
>
> I'm seeing a lot of traffic trying to leave my firewall destined for
> port 6667 at the IPs 10.0.1.128, 10.10.10.10, 1.1.1.1 and 1.3.3.7
> (sounds like l337/elite to me .
>
> Yes - I know the 10.x.x.x traffic isn't going too far.... RFC1918, etc,
> etc.
>
> Various Google searches and searches on the various A/V sites haven't
> turned up a definite answer - just more questions about the same thing.
>
> Can anyone clue me in to the exact trojan/worm/virus this may be and/or
> if they're seeing the same kind of traffic.
>
> Any insight is appreciated....
>
> Thanks.
>
> B


It seem to be somekind of worm, that spread on the irc networks..

Greets
D




Damjan
  Reply With Quote
Old 09-18-2003, 11:44 PM   #3
[ Doc Jeff ]
 
Posts: n/a
Default Re: Port 6667 & 10.0.1.128/1.1.1.1/1.3.3.7
On Thu, 18 Sep 2003 11:32:06 -0400, ex-Zephion
<dl1west-> wrote:

>Hello,
>
>I'm seeing a lot of traffic trying to leave my firewall destined for
>port 6667 at the IPs 10.0.1.128, 10.10.10.10, 1.1.1.1 and 1.3.3.7
>(sounds like l337/elite to me .
>
>Yes - I know the 10.x.x.x traffic isn't going too far.... RFC1918, etc,
>etc.
>
>Various Google searches and searches on the various A/V sites haven't
>turned up a definite answer - just more questions about the same thing.
>
>Can anyone clue me in to the exact trojan/worm/virus this may be and/or
>if they're seeing the same kind of traffic.
>
>Any insight is appreciated....


Sounds a little like the Fizzer worm but most AV software ought to
pick up on it and exterminate

--
http://www.cotse.net - Use it, you know you want to.
If you're too scared to go look for yourself, ask me
about COTSE. I'd be happy to tell you about it.


[ Doc Jeff ]
  Reply With Quote
Old 09-19-2003, 04:33 PM   #4
Mimic
 
Posts: n/a
Default Re: Port 6667 & 10.0.1.128/1.1.1.1/1.3.3.7
"ex-Zephion" <dl1west-> wrote in message
news:...
> Hello,
>
> I'm seeing a lot of traffic trying to leave my firewall destined for
> port 6667 at the IPs 10.0.1.128, 10.10.10.10, 1.1.1.1 and 1.3.3.7
> (sounds like l337/elite to me .
>
> Yes - I know the 10.x.x.x traffic isn't going too far.... RFC1918, etc,
> etc.
>
> Various Google searches and searches on the various A/V sites haven't
> turned up a definite answer - just more questions about the same thing.
>
> Can anyone clue me in to the exact trojan/worm/virus this may be and/or
> if they're seeing the same kind of traffic.
>
> Any insight is appreciated....
>
> Thanks.
>
> B
>


6667 is generally an IRC server, so maybe its an IRC spread worm ?
if you run irc, you could check to see if theres anything (scripts) funny in
your irc dir i guess


--
Mimic

"Without Knowledge you have fear, With fear you create your own nightmares."
"There are 10 types of people in this world. Those that understand Binary,
and those that dont."
"C makes it easy to shoot yourself in the foot. C++ makes it harder, but
when you do, it blows away your whole leg"





Mimic
  Reply With Quote
Old 09-19-2003, 06:11 PM   #5
Chuck
 
Posts: n/a
Default Re: Port 6667 & 10.0.1.128/1.1.1.1/1.3.3.7
On Thu, 18 Sep 2003 11:32:06 -0400, ex-Zephion
<dl1west-> wrote:

>Hello,
>
>I'm seeing a lot of traffic trying to leave my firewall destined for
>port 6667 at the IPs 10.0.1.128, 10.10.10.10, 1.1.1.1 and 1.3.3.7
>(sounds like l337/elite to me .
>
>Yes - I know the 10.x.x.x traffic isn't going too far.... RFC1918, etc,
>etc.
>
>Various Google searches and searches on the various A/V sites haven't
>turned up a definite answer - just more questions about the same thing.
>
>Can anyone clue me in to the exact trojan/worm/virus this may be and/or
>if they're seeing the same kind of traffic.
>
>Any insight is appreciated....
>
>Thanks.
>
>B


Automated detection tools, rather than manual searches of discussion
groups, might be more useful.

If I were you, I'd give Spybot S&D, and HijackThis, a shot. Start
from this article (ignore the title):
http://forums.spywareinfo.com/index.php?showtopic=5187


Chuck

Spam sucks - PLEASE get rid of the spam before emailing me!
Trusted Computing? Right! http://www.againsttcpa.com/
WHAT IS THE CBDTPA? http://www.stoppoliceware.org/



Chuck
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Can not access console port of Cisco 7200 vxr mansurbd Hardware 1 01-12-2009 06:53 PM
How to check current event and port status for Aliwei FXO gateway Robin wang Hardware 0 04-11-2008 09:54 AM
Port 445: Effective/Safe Blocking Samwise General Help Related Topics 0 01-06-2008 09:19 PM
Long, regarding a "lost" COM port smackedass A+ Certification 4 02-05-2007 04:55 PM
non plug and play device on com port? David K A+ Certification 1 07-18-2003 08:38 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46