UDP scans from CodeRed-infected hosts

From: Kyle Maus (sargonat_private)
Date: Tue Aug 07 2001 - 12:29:57 PDT

  • Next message: Ralph Mellor: "Re: more Code Red analysis"

    I am beginning to see UDP probes coming from servers which I had earlier 
    identified as servers infected with CodeRed II.
    
    Looks like things are about to become interesting.....
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Tue Aug 07 2001 - 15:10:44 PDT