Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Port 1027 (tcp/udp) Attack Activity Port 1027 (tcp/udp) Attack Activity

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
[get complete service list]
Port Information
Protocol Service Name
tcp icq icq instant messanger
Top IPs Scanning
TodayYesterday (92) (51) (57) (49) (35) (48) (29) (36) (23) (34) (18) (33) (16) (30) (14) (28) (14) (27) (12) (20)
User Comments
Submitted By Date
Lele 2004-10-28 05:16:08
This is the data contained in the packet: Frame 93 (709 bytes on wire, 709 bytes captured) Time delta from previous packet: 51.351791000 seconds Time since reference or first frame: 1998.591219000 seconds Frame Number: 93 Packet Length: 709 bytes Capture Length: 709 bytes Ethernet II, Src: 00:e0:63:xx:xx:xx, Dst: 00:04:75:xx:xx:xx Destination: 00:04:75:xx:xx:xx (3Com_xx:xx:xx) Source: 00:e0:63:xx:xx:xx (Cabletro_xx:xx:xx) Type: IP (0x0800) Internet Protocol, Src Addr: (, Dst Addr: User Datagram Protocol, Src Port: 1613 (1613), Dst Port: 1027 (1027) DCE RPC Microsoft Messenger Service Operation: NetrSendMessage (0) Server Max Count: 19 Offset: 0 Actual Count: 19 Server: DIPLOMAS Client Max Count: 19 Offset: 0 Actual Count: 19 Client: You Message Max Count: 511 Offset: 0 Actual Count: 511 Message: \n\nObtain a prosperous future, money earning power,and the admiration of all.\n\nDiplomas from prestigious universities based on your present knowledge and life experience.\n\nNo required tests, classes, books, or interviews.\n\n I think it's a mass spam... couse the source ip is forged and my router are logging a lot of traffic like this... Lele from Italy (sorry for my english!)
2004-07-14 01:15:56
Add a comment
CVE Links
CVE # Description