Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted (edited)

I'm seeing loads of these events on a brand new 2008 VM and i'm wondering if anyone else has seen this?

 

It looks like an incoming address that's been configured by APIPA.

 

Anyone help with this is it some kind of multicast traffic?

 

Event ID: 5152

 

The Windows Filtering Platform blocked a packet.

 

Application Information:

Process ID: 1204

Application Name: \device\harddiskvolume1\windows\system32\svchost.exe

 

Network Information:

Direction: Inbound

Source Address: 224.0.0.252

Source Port: 5355

Destination Address: 169.254.154.156

Destination Port: 63435

Protocol: 17

 

Filter Information:

Filter Run-Time ID: 0

Layer Name: Receive/Accept

Layer Run-Time ID: 44

Edited by cookie_monster
Posted
I think I might be getting somewhere. I also noticed this afternoon thousands of bad password attempts even though no staff or students are in. I tracked some down to a new PC that was installed yesterday as part of a new system that I have nothing to do with (supposedly a freshly built XP PC), I installed our AV and it immediately quarantined the conficker work. I'll be confirming this and opening a can of you know what. :mad:
Posted
It was my immediate thought when I noticed svchost and being blocked. It's a trojan alright. A little worrying it's on a newly imaged machine. Hope it's not on all the others!!
Posted (edited)

Yeh I began thinking the same later on as I hadn't noticed these events on the new 2008 servers yesterday when I built them. What really bought it to me was when I rebuilt an XP SP3 test PC from CD media later on and I noticed loads of bad passwords from there as well (of course it had immediatly been infected). Fortunatly all of our other systems are patched and running AV.

 

Lucky 2008 SP2 is patched or I would be rebuilding my new servers :eek:

 

 

EDIT- yep tracked it down to a contractor that came to 'maintain' this particular system.

Edited by cookie_monster
Posted (edited)

I'm still getting loads of these events but i'm pretty sure it's not conficker as i've turned off everthing on our network except one unpatched XP box that isn't getting infected.

 

The Windows Filtering Platform blocked a packet.

 

Application Information:

Process ID: 1004

Application Name: \device\harddiskvolume1\windows\system32\svchost.exe

 

Network Information:

Direction: Inbound

Source Address: 169.254.194.1

Source Port: 53542

Destination Address: 169.254.194.1

Destination Port: 389

Protocol: 6

 

Filter Information:

Filter Run-Time ID: 67026

Layer Name: Receive/Accept

Layer Run-Time ID: 4

 

It's odd as that address isn't in our IP range.

 

 

Ok this starts to explain something, now how do I stop it filling the event logs?

 

http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5157

Edited by cookie_monster

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...