-----Original Message-----
From: Hansen, Kevin [mailto:[EMAIL PROTECTED]
Sent: Wednesday, October 01, 2003 2:19 PM
To: '[EMAIL PROTECTED]'
Subject: [Full-Disclosure] Mystery DNS ChangesWe have seen multiple instances where DHCP enabled workstations have had their DNS reconfigured to point to two of the three addresses listed below. Can anyone else confirm this? Incidents.org is reporting an increase in port 53 traffic over the last two days. Are we looking at the precursor to the next worm?
216.127.92.38
69.57.146.14
69.57.147.175
According to McAfee:
This is the QHosts-1 trojan
http://vil.nai.com/vil/content/v_100719.htm
Paul Schmehl ([EMAIL PROTECTED])
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/~pauls/
Title: Message
- [Full-Disclosure] Mystery DNS Changes Hansen, Kevin
- Re: [Full-Disclosure] Mystery DNS Changes Gary Flynn
- Re: [Full-Disclosure] Mystery DNS Changes Brian Eckman
- Re: [Full-Disclosure] Mystery DNS Changes Russell Fulton
- Re: [Full-Disclosure] Mystery DNS Changes Mary Landesman
- Re: [Full-Disclosure] Mystery DNS Changes Mike Tancsa
- Re: [Full-Disclosure] Mystery DNS Changes Danny Pansters
- Re: [Full-Disclosure] Mystery DNS Changes Joe Stewart
- RE: [Full-Disclosure] Mystery DNS Changes Brown, James (Jim)
- RE: [Full-Disclosure] Mystery DNS Changes Schmehl, Paul L
- RE: [Full-Disclosure] Mystery DNS Changes David Vincent
- RE: [Full-Disclosure] Mystery DNS Changes tom_gordon
- RE: [Full-Disclosure] Mystery DNS Changes Harris, Michael C.
- Re: [Full-Disclosure] Mystery DNS Changes Paul Tinsley
- Re: [Snort-sigs] Re: [Full-Disclosure] Mys... Paul Tinsley
- Re: [Snort-sigs] Re: [Full-Disclosure]... Paul Schmehl
- Re: [Snort-sigs] Re: [Full-Disclo... Paul Tinsley
- Re: [Snort-sigs] Re: [Full-Di... Paul Schmehl
- Re: [Full-Disclosure] Mystery DNS Changes *Hobbit*