Re: New Trojan on the block [CIA Trojan]
"Chris Norton" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Hello everyone, Sorry if this gets posted double but I sent the last one from the wrong email address. Just a follow up. Panda software will find the server [the program that creates the client .exe which infects a users machine] and labels it as Backdoor.Ciadoor.B but the actual client program that infects the machines still goes by undetected. Watch out for unusal network activity on TCP ports 6333, 6334, and 6335. The snort rule posted earlier will work and catch all login attempts to the trojan. I did not specify a port as this can be changed. If anyone has any more information or would like to add please do. ------------------------------------------------------------- Chris Norton - UAT Student Software Engineering Network Defense _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions