Sean’s Obsessions

  • Archives

12 Aug

Worms, Worms, Everywhere

It looks like W32/Blaster is making its rounds. For interests sakes, I’ve started collecting connection attempts to port 135 and 445:

Not sure if the flatline last night was because I lost data when I changed the collection program, or if there was just no attempts (doubtful)

Also updated the extended entry to show a pie chart comparing the sources of infections…

This graph shows the source of the attack, based on the /8 the host comes from. Note a lot of 24/8 hosts, mostly cable modems.

3 Responses to “Worms, Worms, Everywhere”

  1. 1
    Frank Merenda Says:

    Here’s a shot of activity on the ‘net caused by this worm from http://isc.sans.org/. It looks like it’s picking up a lot of momentum today…

    http://isc.sans.org/images/port135percent.png

  2. 2
    Geek Says:

    What tool(s) did you use for collection?

  3. 3
    Sean Says:

    Some perl scripts I wrote… One is a daemon that listens for the connections, and logs them. The other two read the logfile and generate the respective graphs (using GD::Graph).

    Sean

© 2008 Sean’s Obsessions | Entries (RSS) and Comments (RSS)

Powered by Wordpress, design by Web4Sudoku, based on Pinkline byGPS Gazette