Subject: Fw: Complaints related to abouse originating from your network From: "Amjad Siddiqui" To: Date: Thu, April 10, 2003 3:37 am ----- Original Message ----- From: "MisrNet SAE System Administrator" To: "System Administrator" Sent: Monday, April 07, 2003 5:30 PM Subject: Code Red 2 intrusion attempt via your network (202.133.74.170) > Dear Sir, > > You are receiving this notice since your address is listed as the > contact in the APNIC database for IP address 202.133.74.170. > > The following Code Red 2 intrusion attempt was made against MISRNET.COM.EG. > > DATE/TIME: Apr-08-2003 (00:29:54) [UTC] > SOURCE : 202.133.74.170:1322 > DEST : 81.4.28.206 > ATTEMPT : /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3% u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a > > Please advise your user that their system has been compromised and is being > actively utilized as an attack launchpoint against other systems. > > More information regarding these worms can be found at: > http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.html > http://www.sarc.com/avcenter/venc/data/codered.worm.html > http://www.symantec.com/avcenter/venc/data/w32.nimda.a@mm.html > > You can advise your users to find a list of some of helpfull programs > to remove such worms by visiting the following web sites: > http://windowsupdate.microsoft.com/ (Microsoft Windows 95/98 Operating System Updates) > http://www.moosoft.com/download.php (The Cleaner - Trojan Cleaner) > > MisrNet SAE does not specifically recommended nor endorse any specific product > > > Thank you for your prompt attention to this matter. > > -Early Bird v2.6 > (http://www.treachery.net/earlybird/) > > > --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.467 / Virus Database: 266 - Release Date: 4/1/2003