|
-
March 20th, 2004, 04:55 AM
#2
Member
Haven't seen this specifically, but it sure looks like it's a RAT or listening Trojan. It takes commands from those IRC channels (much like the other fools). The destination port of 53 is usually DNS, yes? This is a good tactic because most firewalls will let port 53 in/out unless explicitlly blocked..
Hmm...
SvcHost.exe is a good name to hide a nefarious service. It may be a modified version of BO2K or something else with source available, so maybe a Trojan or virus scanner wouldn't pick it up.
l00p
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|