<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<META NAME="Generator" CONTENT="MS Exchange Server version 5.5.2654.19">
<TITLE>Mystery DNS Changes</TITLE>
</HEAD>
<BODY>
<P><FONT SIZE=2 FACE="Arial">We have seen multiple instances where DHCP enabled workstations have had their DNS reconfigured to point to two of the three addresses listed below. Can anyone else confirm this? Incidents.org is reporting an increase in port 53 traffic over the last two days. Are we looking at the precursor to the next worm?</FONT></P>
<P><FONT SIZE=2 FACE="Arial">216.127.92.38</FONT>
<BR><FONT SIZE=2 FACE="Arial">69.57.146.14</FONT>
<BR><FONT SIZE=2 FACE="Arial">69.57.147.175</FONT>
</P>
<P><FONT SIZE=2 FACE="Arial">-KJH</FONT>
</P>
<BR>
<P><FONT SIZE=2 FACE="Courier New">++++++++++++++++++++++++++</FONT>
<BR><FONT SIZE=2 FACE="Courier New">Kevin J. Hansen</FONT>
<BR><FONT SIZE=2 FACE="Courier New">Architect</FONT>
<BR><FONT SIZE=2 FACE="Courier New">Global Network</FONT>
<BR><FONT SIZE=2 FACE="Courier New">Thomson Legal & Regulatory</FONT>
<BR><FONT SIZE=2 FACE="Courier New">kevin.hansen@thomson.com</FONT>
<BR><FONT SIZE=2 FACE="Courier New">651-687-8466</FONT>
<BR><FONT SIZE=2 FACE="Courier New">++++++++++++++++++++++++++</FONT>
</P>
<BR>
</BODY>
</HTML>