Handler on Duty: Xavier Mertens
Threat Level: green
Loading...
|
|
Submitted By | Date |
---|---|
Comment | |
David Tulo | 2004-04-30 15:49:19 |
There is a proxy or trojan scanner hitting TCP ports 80, 2282, 3128, 3382, 6588, 8000, 8080, and 22788. According to LURHQ, during stage 3 of a Sobig.e worm infection, Wingate proxy software is installed and establishes a WWW proxy on TCP port 2282. Additionally, Sobig.f is reported to change the port of the Wingate WWW proxy to 3382. |
CVE # | Description |
---|