Re: New Trojan

From: Damian Gerow (damian_at_sentex.net)
Date: 10/28/03

  • Next message: Harlan Carvey: "Re: Probable Trojan."
    Date: Tue, 28 Oct 2003 13:17:33 -0500
    To: incidents@securityfocus.com
    
    

    An update...

    Part of our dealing with spamming customers is to move them into a smaller
    IP block for their DSL connection, that denies inbound TCP SYN packets.
    Well, earlier this morning, one of our special ip-pool customers was caught
    spamming. He most definitely didn't do it himself, and he is infected with
    this trojan. I'm trying to figure out if the two (this mornings spam
    attempt and the trojan) are related, or if perhaps he's infected with some
    remote control IRC trojan as well.

    I also just completed a UDP port scan of the infect host, which was
    completely useless. My screen buffer only goes back so far, but every port
    from 64367 and up is marked as 'open'. :(

      - Damian

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_incidents_031023
    and use priority code SF4.
    ----------------------------------------------------------------------------


  • Next message: Harlan Carvey: "Re: Probable Trojan."

    Relevant Pages

    • Job Search Sites Infected
      ... Don Jackson, the SecureWorks researcher who found the collection, ... the Prg Trojan, a piece of malware first seen in the wild in June. ... serves up between one and four exploits designed to infect ...
      (comp.programming)
    • Re: Apparent rash of hacked accounts???
      ... >>There actually was a trojan that did 'infect' many laggard users in just ... >>updates for over a year, ... >>That's why I said it probably is a trojan. ... OTOH I tried opera when a bunch of people said it was the greatest thing ...
      (alt.games.warcraft)
    • Re: Apparent rash of hacked accounts???
      ... > There actually was a trojan that did 'infect' many laggard users in just ... didnt install any of the standard windows ... > That's why I said it probably is a trojan. ... Allakhazam is one of the more useful WoW sites. ...
      (alt.games.warcraft)
    • Re: Norton Firewall 2004
      ... I wonder if Kevin has seen this and whether he can ... >>been infected by a Trojan. ... Even without a virus ... >>would not be able to infect you if you didn't have the ...
      (microsoft.public.security.virus)
    • Re: "Taylor Jimenez" is Joe Jared, the x-no-archive stalker
      ... >> download some file because nobody will go to his trojan infested website ... >> and infect their computers. ... He said trojan infected site, not that the files on his site are infected. ... opinion one way or another on the computer itself. ...
      (sci.psychology.psychotherapy)