Security Incidents mailing list archives
Re: New Trojan
From: Damian Gerow <damian () sentex net>
Date: Tue, 28 Oct 2003 13:17:33 -0500
An update... Part of our dealing with spamming customers is to move them into a smaller IP block for their DSL connection, that denies inbound TCP SYN packets. Well, earlier this morning, one of our special ip-pool customers was caught spamming. He most definitely didn't do it himself, and he is infected with this trojan. I'm trying to figure out if the two (this mornings spam attempt and the trojan) are related, or if perhaps he's infected with some remote control IRC trojan as well. I also just completed a UDP port scan of the infect host, which was completely useless. My screen buffer only goes back so far, but every port from 64367 and up is marked as 'open'. :( - Damian --------------------------------------------------------------------------- Network with over 10,000 of the brightest minds in information security at the largest, most highly-anticipated industry event of the year. Don't miss RSA Conference 2004! Choose from over 200 class sessions and see demos from more than 250 industry vendors. If your job touches security, you need to be here. Learn more or register at http://www.securityfocus.com/sponsor/RSA_incidents_031023 and use priority code SF4. ----------------------------------------------------------------------------
Current thread:
- Re: New Trojan, (continued)
- Re: New Trojan lsi (Oct 27)
- RE: New Trojan Lucretia (Oct 28)
- RE: New Trojan Harlan Carvey (Oct 27)
- Re: New Trojan lsi (Oct 27)
- RE: New Trojan Rob Shein (Oct 25)
- RE: New Trojan Tiago Halm (Oct 26)
- Re: New Trojan Damian Gerow (Oct 27)
- RE: New Trojan Rob Shein (Oct 28)
- Re: New Trojan Damian Gerow (Oct 28)
- Re: New Trojan Brian Eckman (Oct 28)
- Re: New Trojan Damian Gerow (Oct 28)
- Re: New Trojan Damian Gerow (Oct 28)
- Re: New Trojan Russell Fulton (Oct 28)
- RE: New Trojan Rob Shein (Oct 28)
- RE: New Trojan Jerry Heidtke (Oct 25)
- RE: New Trojan John Ives (Oct 26)
- Re: New Trojan Grzegorz (Oct 25)
- Re: New Trojan Harlan Carvey (Oct 27)
- Re: New Trojan sean (Oct 25)
- Re: New Trojan Jay Castaldo (Oct 27)
- Re: New Trojan Damian Gerow (Oct 27)
- RE: New Trojan Chris Fussell (Oct 27)
- RE: New Trojan Tran, John (Oct 27)