cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
366
Views
0
Helpful
5
Replies

ICMP response for www.instituto.com.br from 127.0.0.1 !!!

ahvn
Level 1
Level 1

Dear all,

When I ping www.instituto.com.br from my 4500 series router ( IOS 12.1 ), I find the ICMP response coming from 127.0.0.1.I tried this from many routers world wide and I found the same observation.When I searched the net I found its some virus called AttackDos.php.This observation I found in almost every PC in my network and this is propagating unwanted traffic inside my network congesting many of my links.

Does anyone know how to contain this thing.Those who have faced similiar experience and fixed it kindly help me out.

Thanks in advance.

Rgds,

Homin

5 Replies 5

Pavel Bykov
Level 5
Level 5

Are you sure this is a virus?

I tried to ping this from many locations, including from PC's located inside of the corporate network, an i also get that response. Maybe it is some kind of protection against ICMP?

Hello Homin,

I think it might very well be a virus. Check out the following link for info on the WORM_YAHA.AA worm which creates 127.0.0.1 addresses for websites.

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_YAHA.AA&VSect=T

Regards,

GP

I dont think this is a virus. The DNS for this URL is pointing to 127.0.0.1

Regards.

Rais,

that is exactly what the worm does, it creates a local hosts file with entries for websites pointing to 127.0.0.1.

Regards,

Georg

But this is the entry in the DNS server for this site. Does this mean the virus has corrupted the DNS server? Though it is possible, I highly doubt it, because all of the customers for that ISP would have been affected.

Try to traceroute from Princeton University. They also resolve it to 127.0.0.1

http://www.net.princeton.edu/traceroute.html

Other tools to verify this info:

http://www.netdept.com/netTools.jsp

Thanks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: