Hello: Today I started msn messenger and few seconds later I got an attack detected by Norton Internet Security. Here are some details from my log files:
Quote:
Details: Rule "Default Block Bla Trojan horse" stealthed (e450.voice.microsoft.com(64.4.12.200),1042)
Inbound UDP packet
Local address,service is (jagermeister(192.168.1.8),1042)
Remote address,service is (e450.voice.microsoft.com(64.4.12.200),7001)
Process name is "C:\Program Files\MSN Messenger\msnmsgr.exe"
Results from whois 64.4.12.200:
What could this be?? My guesses:Quote:
OrgName: MS Hotmail
OrgID: MSHOTM
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
NetRange: 64.4.0.0 - 64.4.63.255
CIDR: 64.4.0.0/18
NetName: HOTMAIL
NetHandle: NET-64-4-0-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.HOTMAIL.COM
NameServer: NS3.HOTMAIL.COM
NameServer: NS2.HOTMAIL.COM
NameServer: NS4.HOTMAIL.COM
Comment:
RegDate: 1999-11-24
Updated: 2003-06-27
TechHandle: MSFTP-ARIN
TechName: MSFT-POC
TechPhone: +1-425-882-8080
TechEmail: [email protected]
OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: [email protected]
OrgTechHandle: MSFTP-ARIN
OrgTechName: MSFT-POC
OrgTechPhone: +1-425-882-8080
OrgTechEmail: [email protected]
# ARIN WHOIS database, last updated 2004-07-30 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
1. Regular traffic between msn messenger and hotmail and my firewall picked it up as an attack.
2. Real attack from someone spoofing hotmail's IP.
What is the supposed trojan that is being used to attack me? Any guesses if this was just a port scan or something more dangerous? What can be exploited in UDP port 1042?
I know I am asking too many questions but I am very curious to know what this is about.
cheers,
J
