The infected honeypot was sending a 376 byte
long UDP packet to port 1434 using random
targets at a very high rate.
20:00:48.854154 213.112.161.133.1401 > 192.168.20.3.1434: udp 376
20:00:48.870997 arp who-has 192.168.20.254 tell 192.168.20.3
20:00:48.871056 arp reply 192.168.20.254 is-at 0:50:fc:2b:1b:c5
20:00:48.871355 192.168.20.3.1034 > 89.146.178.104.1434: udp 376
20:00:48.871397 192.168.20.3.1034 > 25.231.4.116.1434: udp 376
20:00:48.871429 192.168.20.3.1034 > 217.232.208.46.1434: udp 376
20:00:48.871468 192.168.20.3.1034 > 153.227.35.52.1434: udp 376
20:00:48.871502 192.168.20.3.1034 > 89.243.5.31.1434: udp 376
20:00:48.871536 192.168.20.3.1034 > 25.196.206.153.1434: udp 376
20:00:48.871585 192.168.20.3.1034 > 217.81.39.243.1434: udp 376
20:00:48.871607 192.168.20.3.1034 > 153.168.4.22.1434: udp 376
20:00:48.871642 192.168.20.3.1034 > 89.164.183.124.1434: udp 376
20:00:48.871683 192.168.20.3.1034 > 25.177.189.198.1434: udp 376
20:00:48.871715 192.168.20.3.1034 > 217.138.78.170.1434: udp 376
20:00:48.871753 192.168.20.3.1034 > 153.253.178.6.1434: udp 376
20:00:48.871787 192.168.20.3.1034 > 89.165.64.248.1434: udp 376
20:00:48.871821 192.168.20.3.1034 > 25.174.102.187.1434: udp 376
20:00:48.871857 192.168.20.3.1034 > 217.147.135.166.1434: udp 376
20:00:48.871892 192.168.20.3.1034 > 153.226.107.83.1434: udp 376
20:00:48.871928 192.168.20.3.1034 > 89.246.233.221.1434: udp 376
20:00:48.871970 192.168.20.3.1034 > 25.187.238.246.1434: udp 376
20:00:48.872002 192.168.20.3.1034 > 217.108.99.62.1434: udp 376
20:00:48.872047 192.168.20.3.1034 > 153.87.124.124.1434: udp 376
20:00:48.872075 192.168.20.3.1034 > 89.151.204.32.1434: udp 376
20:00:48.872119 192.168.20.3.1034 > 25.216.10.68.1434: udp 376
20:00:48.872150 192.168.20.3.1034 > 217.21.195.37.1434: udp 376
20:00:48.872190 192.168.20.3.1034 > 153.92.65.42.1434: udp 376
20:00:48.872225 192.168.20.3.1034 > 89.136.209.123.1434: udp 376
20:00:48.872266 192.168.20.3.1034 > 25.5.0.86.1434: udp 376
20:00:48.872302 192.168.20.3.1034 > 217.142.215.150.1434: udp 376
20:00:48.872338 192.168.20.3.1034 > 153.241.39.178.1434: udp 376
20:00:48.872380 192.168.20.3.1034 > 89.201.177.226.1434: udp 376
20:00:48.872415 192.168.20.3.1034 > 25.66.163.117.1434: udp 376
20:00:48.872453 192.168.20.3.1034 > 217.215.33.75.1434: udp 376
20:00:48.872489 192.168.20.3.1034 > 153.22.173.43.1434: udp 376
20:00:48.872524 192.168.20.3.1034 > 89.90.246.66.1434: udp 376
20:00:48.872563 192.168.20.3.1034 > 25.143.89.62.1434: udp 376
20:00:48.872602 192.168.20.3.1034 > 217.240.114.68.1434: udp 376
20:00:48.872637 192.168.20.3.1034 > 153.203.93.21.1434: udp 376
20:00:48.872675 192.168.20.3.1034 > 89.59.248.148.1434: udp 376
20:00:48.872710 192.168.20.3.1034 > 25.236.23.107.1434: udp 376
20:00:48.872746 192.168.20.3.1034 > 217.217.235.101.1434: udp 376
20:00:48.872791 192.168.20.3.1034 > 153.16.215.137.1434: udp 376
20:00:48.872825 192.168.20.3.1034 > 89.108.224.60.1434: udp 376
20:00:48.872860 192.168.20.3.1034 > 25.89.99.179.1434: udp 376
20:00:48.872898 192.168.20.3.1034 > 217.146.253.220.1434: udp 376
20:00:48.872933 192.168.20.3.1034 > 153.229.197.4.1434: udp 376
20:00:48.872968 192.168.20.3.1034 > 89.237.167.187.1434: udp 376
20:00:48.873006 192.168.20.3.1034 > 25.214.80.184.1434: udp 376
20:00:48.873049 192.168.20.3.1034 > 217.27.105.90.1434: udp 376
20:00:48.873082 192.168.20.3.1034 > 153.74.231.183.1434: udp 376
20:00:48.873120 192.168.20.3.1034 > 89.190.23.176.1434: udp 376
20:00:48.873156 192.168.20.3.1034 > 25.99.133.1.1434: udp 376
20:00:48.873190 192.168.20.3.1034 > 217.116.63.27.1434: udp 376
20:00:48.873228 192.168.20.3.1034 > 153.63.8.112.1434: udp 376
20:00:48.873268 192.168.20.3.1034 > 89.223.200.39.1434: udp 376
20:00:48.873307 192.168.20.3.1034 > 25.0.54.10.1434: udp 376
20:00:48.873344 192.168.20.3.1034 > 217.157.225.193.1434: udp 376
20:00:48.873378 192.168.20.3.1034 > 153.196.5.10.1434: udp 376
20:00:48.873413 192.168.20.3.1034 > 89.80.36.64.1434: udp 376
20:00:48.873453 192.168.20.3.1034 > 25.173.39.94.1434: udp 376
20:00:48.873492 192.168.20.3.1034 > 217.150.0.255.1434: udp 376
20:00:48.873533 192.168.20.3.1034 > 153.217.204.119.1434: udp 376
20:00:48.873573 192.168.20.3.1034 > 89.17.99.23.1434: udp 376
20:00:48.873605 192.168.20.3.1034 > 25.106.175.198.1434: udp 376
20:00:48.873642 192.168.20.3.1034 > 217.95.157.10.1434: udp 376
Up to Oct 2003, our IDS still picks up some MSSQL worm

References:
http://www.cert.org/advisories/CA-2003-04.html
http://www.techie.hopto.org/sqlworm.html
http://isc.incidents.org/analysis.html?id=180