I have a frame-relay network routed with Cisco 1700's and 2600's. We have been compromised by the OPA worm. According to the Mcaffee write up, this worm attempts to contact a website and download new versions of itself. I am working on eradication, but in the meantime this thing is flooding my frame-relay resulting in unbelieveable latency. Below is further information including an IP capture of the traffic leaving my web server. Is there anyway I can configure my routers to deny these requests while still allowing legitimate traffic? It appears the target port is 137 however I'm not familiar with IP and don't know if this is a commonly used port.
This is a windows based network. WINS is used for host resolution. IP schema is 192.168.*.* class. Internet is accessed via proxy with NO DNS running on internal network.
Currently no access lists configured on routers.
AgentName, Event Date Time, Destination IP, IP Protocol, Target Port, Issue Description, Source Port, Event Count
ridgway, 3 FEB 2003 08:46:30, 217.41.x.x, 17, 137, W32.Opaserv Worm?, 3611, 1
kenh, 3 FEB 2003 06:01:56, 68.144.x.x, 17, 137, W32.Opaserv Worm?, 3563, 1
Redbird, 3 FEB 2003 14:58:28, 24.88.x.x, 17, 137, W32.Opaserv Worm?, 3563, 1
StockPro, 3 FEB 2003 08:59:24, 68.145.x.x, 17, 137, W32.Opaserv Worm?, 3563, 1
Kostamogen, 3 FEB 2003 08:48:22, 68.145.x.x, 17, 137, W32.Opaserv Worm?, 3563, 1
TheBrit, 3 FEB 2003 06:55:19, 63.201.x.x, 17, 137, W32.Opaserv Worm?, 2972, 1
diehardnascar, 3 FEB 2003 00:04:39, 66.156.x.x, 6, 137, W32.Opaserv Worm?, 3502, 1
diehardnascar, 3 FEB 2003 00:04:39, 66.156.x.x, 6, 137, W32.Opaserv Worm?, 3502, 1
diehardnascar, 3 FEB 2003 00:04:39, 66.156.x.x, 6, 137, W32.Opaserv Worm?, 3502, 1
P.K.Y.Assoc., 3 FEB 2003 19:23:42, 64.65.x.x, 17, 137, W32.Opaserv Worm?, 4273, 1
This is a windows based network. WINS is used for host resolution. IP schema is 192.168.*.* class. Internet is accessed via proxy with NO DNS running on internal network.
Currently no access lists configured on routers.
AgentName, Event Date Time, Destination IP, IP Protocol, Target Port, Issue Description, Source Port, Event Count
ridgway, 3 FEB 2003 08:46:30, 217.41.x.x, 17, 137, W32.Opaserv Worm?, 3611, 1
kenh, 3 FEB 2003 06:01:56, 68.144.x.x, 17, 137, W32.Opaserv Worm?, 3563, 1
Redbird, 3 FEB 2003 14:58:28, 24.88.x.x, 17, 137, W32.Opaserv Worm?, 3563, 1
StockPro, 3 FEB 2003 08:59:24, 68.145.x.x, 17, 137, W32.Opaserv Worm?, 3563, 1
Kostamogen, 3 FEB 2003 08:48:22, 68.145.x.x, 17, 137, W32.Opaserv Worm?, 3563, 1
TheBrit, 3 FEB 2003 06:55:19, 63.201.x.x, 17, 137, W32.Opaserv Worm?, 2972, 1
diehardnascar, 3 FEB 2003 00:04:39, 66.156.x.x, 6, 137, W32.Opaserv Worm?, 3502, 1
diehardnascar, 3 FEB 2003 00:04:39, 66.156.x.x, 6, 137, W32.Opaserv Worm?, 3502, 1
diehardnascar, 3 FEB 2003 00:04:39, 66.156.x.x, 6, 137, W32.Opaserv Worm?, 3502, 1
P.K.Y.Assoc., 3 FEB 2003 19:23:42, 64.65.x.x, 17, 137, W32.Opaserv Worm?, 4273, 1