[From nobody Fri Oct  9 17:20:48 2009
X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on stamps.cs.ucsb.edu
X-Spam-Level: 
X-Spam-Status: No, score=-4.0 required=5.0 tests=HTML_MESSAGE,
	RCVD_IN_DNSWL_MED shortcircuit=no autolearn=failed version=3.2.5
Received: from stamps.cs.ucsb.edu (stamps.cs.ucsb.edu [128.111.41.14])
	by letters.cs.ucsb.edu (8.13.1/8.13.1) with ESMTP id n99NFvdX000390
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK);
	Fri, 9 Oct 2009 16:15:57 -0700
Received: from Waldron (waldron.cs.ucsb.edu [128.111.41.237])
	by stamps.cs.ucsb.edu (8.13.1/8.13.1) with ESMTP id n99NFrUw025847;
	Fri, 9 Oct 2009 16:15:53 -0700
From: &quot;Matthew Turk&quot; &lt;mturk@cs.ucsb.edu&gt;
To: &quot;'Andreas Boschke'&quot; &lt;andreas@cs.ucsb.edu&gt;
Cc: &quot;'Tobias Hollerer'&quot; &lt;holl@cs.ucsb.edu&gt;
References: &lt;CA2D7AD7-0E56-4368-AB51-78C5B4DCB3A5@cs.ucsb.edu&gt;
In-Reply-To: &lt;CA2D7AD7-0E56-4368-AB51-78C5B4DCB3A5@cs.ucsb.edu&gt;
Subject: RE: [COMS #28641] [UCSB-OIT #165624] 128.111.28.95 Infected With
	Conficker
Date: Fri, 9 Oct 2009 16:15:38 -0700
Organization: UCSB
Message-ID: &lt;04b201ca4936$69f7f580$3de7e080$@ucsb.edu&gt;
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary=&quot;----=_NextPart_000_04B3_01CA48FB.BD991D80&quot;
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AcpJNTcZD3QoHNyWSeO7j6j1HDc1cAAAPLiA
Content-Language: en-us
X-Greylist: Sender succeeded STARTTLS authentication, not delayed by
	milter-greylist-4.0a6 (letters.cs.ucsb.edu [128.111.41.13]);
	Fri, 09 Oct 2009 16:15:57 -0700 (PDT)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.0a6
	(stamps.cs.ucsb.edu [128.111.41.14]);
	Fri, 09 Oct 2009 16:15:53 -0700 (PDT)
X-Virus-Scanned: clamav-milter 0.95.1 at stamps
X-Virus-Status: Clean

This is a multi-part message in MIME format.

------=_NextPart_000_04B3_01CA48FB.BD991D80
Content-Type: text/plain;
	charset=&quot;us-ascii&quot;
Content-Transfer-Encoding: 7bit

Andreas,

 

Can you tell us anything more about the machine? MAC address or location?
(We have two lab locations: trailer and Elings Hall).

 

Thanks,

            Matthew

 

From: Andreas Boschke [mailto:andreas@cs.ucsb.edu] 
Sent: Friday, October 09, 2009 4:07 PM
To: Tobias Hollerer; Matthew Turk
Subject: [COMS #28641] [UCSB-OIT #165624] 128.111.28.95 Infected With
Conficker

 

Hi Tobias and Matthew:

 

Would you please ask your students to fix this please?

 

Thanks, 

 

-Andreas 

 

On Fri Oct 09 10:06:55 2009, security@ucsb.edu wrote:

&gt; Greetings,

&gt; 

&gt; 128.111.28.95 is infected with the Conficker worm. Here is a sample of

&gt; the worm reporting to a controller:

&gt; 

&gt; T 2009/10/08 15:28:53.201435 128.111.28.95:54445 -&gt; 83.68.16.6:80 [AP]

&gt; GET /search?q=0 HTTP/1.0.

&gt; User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1;

&gt; .NET CLR 2.0.50727; .NET CLR 1.0.3705; .NET CLR 3.0.04506.648; .NET

&gt; CLR 3.5.21022).

&gt; Host: 83.68.16.6.

&gt; Pragma: no-cache.

&gt; .

&gt; 

&gt; Please investigate and advise.

&gt; 

 


------=_NextPart_000_04B3_01CA48FB.BD991D80
Content-Type: text/html;
	charset=&quot;us-ascii&quot;
Content-Transfer-Encoding: quoted-printable

&lt;html xmlns:v=3D&quot;urn:schemas-microsoft-com:vml&quot; =
xmlns:o=3D&quot;urn:schemas-microsoft-com:office:office&quot; =
xmlns:w=3D&quot;urn:schemas-microsoft-com:office:word&quot; =
xmlns:m=3D&quot;http://schemas.microsoft.com/office/2004/12/omml&quot; =
xmlns=3D&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;META HTTP-EQUIV=3D&quot;Content-Type&quot; CONTENT=3D&quot;text/html; =
charset=3Dus-ascii&quot;&gt;
&lt;meta name=3DGenerator content=3D&quot;Microsoft Word 12 (filtered medium)&quot;&gt;
&lt;style&gt;
&lt;!--
 /* Font Definitions */
 @font-face
	{font-family:Helvetica;
	panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
	{font-family:&quot;Cambria Math&quot;;
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-reply;
	font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
	color:#000099;
	font-weight:normal;
	font-style:normal;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.Section1
	{page:Section1;}
--&gt;
&lt;/style&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=3D&quot;edit&quot; spidmax=3D&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=3D&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=3D&quot;edit&quot; data=3D&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=3DEN-US link=3Dblue vlink=3Dpurple style=3D'word-wrap: =
break-word;
-webkit-nbsp-mode: space;-webkit-line-break: after-white-space'&gt;

&lt;div class=3DSection1&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:#000099'&gt;Andreas,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:#000099'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:#000099'&gt;Can you tell us anything more about the machine? MAC =
address or
location? (We have two lab locations: trailer and Elings =
Hall).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:#000099'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:#000099'&gt;Thanks,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:#000099'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbs=
p;&amp;nbsp; Matthew&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:#000099'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in'&gt;

&lt;p class=3DMsoNormal&gt;&lt;b&gt;&lt;span =
style=3D'font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;=
&lt;/b&gt;&lt;span
style=3D'font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt; Andreas =
Boschke
[mailto:andreas@cs.ucsb.edu] &lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Friday, October 09, 2009 4:07 PM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; Tobias Hollerer; Matthew Turk&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; [COMS #28641] [UCSB-OIT #165624] 128.111.28.95 Infected =
With
Conficker&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=3DMsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=3DMsoNormal&gt;Hi Tobias and Matthew:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;Would you please ask your students to fix this =
please?&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;Thanks,&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;-Andreas&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;On
Fri Oct 09 10:06:55 2009, &lt;a =
href=3D&quot;mailto:security@ucsb.edu&quot;&gt;security@ucsb.edu&lt;/a&gt;
wrote:&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
Greetings,&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;&amp;nbsp;=
&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
128.111.28.95 is infected with the Conficker worm. Here is a sample =
of&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
the worm reporting to a controller:&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;&amp;nbsp;=
&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
T 2009/10/08 15:28:53.201435 128.111.28.95:54445 -&amp;gt; 83.68.16.6:80 =
[AP]&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
GET /search?q=3D0 HTTP/1.0.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; =
SV1;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
.NET CLR 2.0.50727; .NET CLR 1.0.3705; .NET CLR 3.0.04506.648; =
.NET&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
CLR 3.5.21022).&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
Host: 83.68.16.6.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
Pragma: no-cache.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;&amp;nbsp;=
&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;
Please investigate and advise.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&amp;gt;&amp;nbsp;=
&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=3DMsoNormal&gt;&lt;span =
style=3D'font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;'&gt;&lt;o:p&gt;&amp;nbsp=
;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;

------=_NextPart_000_04B3_01CA48FB.BD991D80--
]