I'm puzzled by this one so I thought I'd send it out to the list to
see if you all could provide me some clues. I regularly get UDP
connection attempts that are simply messenger spam. We all do. But,
some of them start out trying to send to the regular messenger ports,
(1024 - 1031...). And, then, it appears, when that doesn't work it
sends exactly two packets to UDP ports 4081 and 2.
I did some searching on dshield's database, and I'm far from being the
only one that is being probed on those ports from those China based hosts.
So, my question is, what would the purpose be to send to those ports?
As far as I know, Windows messenger wouldn't normally be listening on
those ports, so why bother sending to them?
As far as I can tell the payload is identical between the port 4081 and
port 2 packets but I haven't had the time to dissect the header
information to see if there is anything interesting in there. (If no
one else does, I will try to after tomorrow)
Here are the two packets if someone that has more time than myself is
interested in dissecting the header:
07:16:59.639510 IP (tos 0x0, ttl 48, id 0, offset 0, flags [DF], proto
17, length: 381) 202.111.173.85.42022 > 1.1.1.1.4081: [udp sum ok] UDP,
length 353
0x0000: 4500 017d 0000 4000 3011 4355 ca6f ad55 E..}..@.0.CU.o.U
0x0010: 0101 0101 a426 0ff1 0169 7e86 0400 2800 ...}.&...i~...(.
0x0020: 1000 0000 0000 0000 0000 0000 0000 0000 ................
0x0030: 0000 0000 f891 7b5a 00ff d011 a9b2 00c0 ......{Z........
0x0040: 4fb6 e6fc 0000 0000 0000 0000 0000 0000 O...............
0x0050: 0000 0000 0000 0000 0100 0000 0000 0000 ................
0x0060: 0000 ffff ffff 1101 0000 0000 1000 0000 ................
0x0070: 0000 0000 1000 0000 5359 5354 454d 0000 ........SYSTEM..
0x0080: 0000 0000 0000 0000 1000 0000 0000 0000 ................
0x0090: 1000 0000 414c 4552 5400 0000 0000 0000 ....ALERT.......
0x00a0: 0000 0000 cd00 0000 0000 0000 cd00 0000 ................
0x00b0: 5354 4f50 2120 5379 7374 656d 2068 6173 STOP!.System.has
0x00c0: 2065 6e63 6f75 6e74 6572 6564 2061 6e20 .encountered.an.
0x00d0: 496e 7465 726e 616c 2045 7272 6f72 0a59 Internal.Error.Y
0x00e0: 6f75 7220 7265 6769 7374 7279 2069 7320 our.registry.is.
0x00f0: 636f 7272 7570 7465 642e 0a0a 5765 2072 corrupted...We.r
0x0100: 6563 6f6d 6d65 6e64 2061 2063 6f6d 706c ecommend.a.compl
0x0110: 6574 6520 7379 7374 656d 2073 6361 6e2e ete.system.scan.
0x0120: 0a0a 5669 7369 740a 0a77 7777 2e54 6865 ..Visit..
www.The
0x0130: 5265 6746 6978 6572 2e63 6f6d 0a0a 546f RegFixer.com..To
0x0140: 2072 6570 6169 7220 6e6f 770a 0a0a 4641 .repair.now...FA
0x0150: 494c 5552 4520 544f 2041 4354 204e 4f57 ILURE.TO.ACT.NOW
0x0160: 204d 4159 204c 4541 4420 544f 2053 5953 .MAY.LEAD.TO.SYS
0x0170: 5445 4d20 4641 494c 5552 4521 00 TEM.FAILURE!.
07:16:59.642424 IP (tos 0x0, ttl 48, id 0, offset 0, flags [DF], proto
17, length: 381) 202.111.173.85.42022 > 1.1.1.1.2: [udp sum ok] UDP,
length 353
0x0000: 4500 017d 0000 4000 3011 4355 ca6f ad55 E..}..@.0.CU.o.U
0x0010: 0101 0101 a426 0002 0169 8e75 0400 2800 ...}.&...i.u..(.
0x0020: 1000 0000 0000 0000 0000 0000 0000 0000 ................
0x0030: 0000 0000 f891 7b5a 00ff d011 a9b2 00c0 ......{Z........
0x0040: 4fb6 e6fc 0000 0000 0000 0000 0000 0000 O...............
0x0050: 0000 0000 0000 0000 0100 0000 0000 0000 ................
0x0060: 0000 ffff ffff 1101 0000 0000 1000 0000 ................
0x0070: 0000 0000 1000 0000 5359 5354 454d 0000 ........SYSTEM..
0x0080: 0000 0000 0000 0000 1000 0000 0000 0000 ................
0x0090: 1000 0000 414c 4552 5400 0000 0000 0000 ....ALERT.......
0x00a0: 0000 0000 cd00 0000 0000 0000 cd00 0000 ................
0x00b0: 5354 4f50 2120 5379 7374 656d 2068 6173 STOP!.System.has
0x00c0: 2065 6e63 6f75 6e74 6572 6564 2061 6e20 .encountered.an.
0x00d0: 496e 7465 726e 616c 2045 7272 6f72 0a59 Internal.Error.Y
0x00e0: 6f75 7220 7265 6769 7374 7279 2069 7320 our.registry.is.
0x00f0: 636f 7272 7570 7465 642e 0a0a 5765 2072 corrupted...We.r
0x0100: 6563 6f6d 6d65 6e64 2061 2063 6f6d 706c ecommend.a.compl
0x0110: 6574 6520 7379 7374 656d 2073 6361 6e2e ete.system.scan.
0x0120: 0a0a 5669 7369 740a 0a77 7777 2e54 6865 ..Visit..
www.The
0x0130: 5265 6746 6978 6572 2e63 6f6d 0a0a 546f RegFixer.com..To
0x0140: 2072 6570 6169 7220 6e6f 770a 0a0a 4641 .repair.now...FA
0x0150: 494c 5552 4520 544f 2041 4354 204e 4f57 ILURE.TO.ACT.NOW
0x0160: 204d 4159 204c 4541 4420 544f 2053 5953 .MAY.LEAD.TO.SYS
0x0170: 5445 4d20 4641 494c 5552 4521 00 TEM.FAILURE!.
--
Mark