RE: 'Code Red' does not seem to be scanning for IIS

From: Emre Yildirim (emreat_private)
Date: Thu Jul 19 2001 - 17:00:11 PDT

  • Next message: Tony Langdon: "RE: Mitigating some of the effects of the Code Red worm"

    > the worm just tries port 80 on ip's. doesnt care if its IIS or not.
    
    
    This is weird.  I just checked the www logs of one of our webservers, and
    found about 144 hits in a 5 hours time span.  There seems to be no pattern
    either; the IPs are all random (although there were a lot of .cn and .tw
    as wellas DSL hosts).  One thing I've noticed is that the hits only appear at
    certaintimes.  I.e. from 15:25 to 15:31 we got about 27 hits, and there are some
    other noticable times like 16:50 to 17:15.  Maybe it's just a coincidence.
    
    
    --
    emreat_private
    
    (PS:  Perhaps this should be posted to incidents@)
    



    This archive was generated by hypermail 2b30 : Thu Jul 19 2001 - 18:21:14 PDT