Re: New Trojan on the block [CIA Trojan]

"Chris Norton" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Hello everyone,

Sorry if this gets posted double but I sent the last one from the wrong
email address. Just a follow up. Panda software will find the server [the
program that creates the client .exe which infects a users machine] and
labels it as Backdoor.Ciadoor.B but the actual client program that infects
the machines still goes by undetected. Watch out for unusal network activity
on TCP ports 6333, 6334, and 6335. The snort rule posted earlier will work
and catch all login attempts to the trojan. I did not specify a port as this
can be changed. If anyone has any more information or would like to add
please do.

-------------------------------------------------------------
Chris Norton - UAT Student Software Engineering Network Defense
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.