Compromized Windows NT machine?

From: GabyHornik@lotus.iot.dtag.de
Date: 07/26/02


From: GabyHornik@lotus.iot.dtag.de
To: incidents@securityfocus.com
Date: Fri, 26 Jul 2002 11:08:55 +0200

Hello!

Recently while looking over some firewall logs I encountered some strange
traffic from a WinNT machine.
Every 90 minutes it tries to connect to a bulk of machines to port 4665
(normally eDonkey clients).
That alone isn't strange at all, but there's coming a bulk of other ports
with it, in detail
udp/smtp
udp/8004
udp/8665
udp/7665
udp/4765
udp/84
udp/2004
udp/6890
udp/28014
udp/6670

udp/smtp is coming nearly every minute, the rest every 90 minutes.

Has anybody seen this before or can anybody identify this as a trojan?

Thanks, Gaby

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Compromized Windows NT machine?
    ... it's a normal executable or some 'strange new code'. ... > That alone isn't strange at all, but there's coming a bulk of other ports ... > udp/smtp is coming nearly every minute, ...
    (Incidents)
  • Re: Performance issue concerning about "insert" statement on Pervasive 2000i
    ... Take a look at bcp utility, which must exist for your db, or at SqlBulkCopy ... which are better suitable for bulk inserts ... I am facing a very strange "problem" on the captioned issue, ... Actually I am developing an interface which read ...
    (microsoft.public.dotnet.languages.vb)
  • Re: Farfugium japonicum Aureomaculatum
    ... just will not 'bulk up'. ... It's not exactly a big seller but it seems strange that it really doesn't want to do much but sit and sulk! ...
    (uk.rec.gardening)
  • Re: OT: interesting global warming quote found elsewhwere
    ... very nasty motives to individuals that I just don't see as being ... They are some VERY strange people about. ... The bulk of FALSE or manufactured evidence you mean. ...
    (sci.electronics.design)