Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Jan 8th, 2009, 11:55am
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   Lots of port activity... anyone else see these?
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Lots of port activity... anyone else see these?  (Read 372 times)
Ian
Stole All the Forum Stars
********



Good things come to those who wait ...

   


Posts: 2913
Lots of port activity... anyone else see these?
« on: Jan 7th, 2004, 8:51pm »
Quote Quote  Modify Modify

Okay, here's the latest 'craze'...
 
Machines infect with RAT are hitting my IP right now, from all over the place (Belgium and Germany mostly, but also UK and Italy)
 
Something new - there seems to be an exploit (won't call it more than that for the moment) that uses TCP 1711 (registered service=pptconference: info at http://isc.incidents.org/port_details.html?port=1711), mostly from sources in the Netherlands and Hungary (one in each country is quite persistent, at 12 in the last 5 mins). This maybe akin to the P2P exploits used by many malware writers, but specifically targetted at businesses and SOHO users. There's a UDP service on this port as well, but I'm only seeing TCP for now, indicating endpoint-to-endpoint connection; just the sort of thing malware needs to spread.
 
There's also something banging away on TCP 20237, from domain 'flanagan.ugr.es', that I can't ID yet...
 
Anyone else seeing these?
« Last Edit: Jan 7th, 2004, 8:51pm by Ian » IP Logged

... but crap arrives pretty much straight away.
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register