Re: Compromized Windows NT machine?

From: Frank Knobbe (fknobbe@knobbeits.com)
Date: 07/27/02


From: Frank Knobbe <fknobbe@knobbeits.com>
To: GabyHornik@lotus.iot.dtag.de
Date: 26 Jul 2002 23:01:31 -0500


Why don't you run fport.exe (downloadable from FoundStone) to find out
which applications are listening on these ports? That should tell you if
it's a normal executable or some 'strange new code'.

Regards,
Frank

On Fri, 2002-07-26 at 04:08, GabyHornik@lotus.iot.dtag.de wrote:
> Hello!
>
> Recently while looking over some firewall logs I encountered some strange
> traffic from a WinNT machine.
> Every 90 minutes it tries to connect to a bulk of machines to port 4665
> (normally eDonkey clients).
> That alone isn't strange at all, but there's coming a bulk of other ports
> with it, in detail
> udp/smtp
> udp/8004
> udp/8665
> udp/7665
> udp/4765
> udp/84
> udp/2004
> udp/6890
> udp/28014
> udp/6670
>
> udp/smtp is coming nearly every minute, the rest every 90 minutes.
>
> Has anybody seen this before or can anybody identify this as a trojan?
>
> Thanks, Gaby
>
>
> ----------------------------------------------------------------------------
> This list is provided by the SecurityFocus ARIS analyzer service.
> For more information on this free incident handling, management
> and tracking system please see: http://aris.securityfocus.com






Relevant Pages

  • Re: some weird stuff found
    ... > In the last few days I started noticing strange things. ... FreeBSD machines. ... to see what is bound to those ports. ... I am running xdm but I only allowed connections from ...
    (FreeBSD-Security)
  • Re: PING--> David H Lipman.
    ... > | Hello David. ... > NameServer: DNS01.SAVVIS.NET ... That is strange indeed! ... some of the ports is the same ports that MyNetwatchman is listen to, ...
    (microsoft.public.security.virus)
  • Random unprivileged TCP ports below 5000 kind-of open for a fraction of a second
    ... I have a strange problem, ... I scanned localhost TCP ports with nmap and I saw that ... I found out that by default nmap doesn't scan every ... there were 2) ports which were reported by nmap as ...
    (Incidents)
  • Re: BUG: Unusual TCP Connect() results.
    ... > kernels do not return the same strange results. ... > strangely ports which are NOT open are being reported as open. ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)
  • RE: funny packets
    ... While CVSuppin' ports i caught some strange packets: ... 195.25.44.186:4828 213.227.128.244:4662 in via tun0 ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)