Handler on Duty: Didier Stevens
Threat Level: green
Loading...
|
|
Submitted By | Date |
---|---|
Comment | |
David Tulo | 2004-04-30 15:49:02 |
There is a proxy or trojan scanner hitting TCP ports 80, 2282, 3128, 3382, 6588, 8000, 8080, and 22788. According to LURHQ, during stage 3 of a Sobig.e worm infection, Wingate proxy software is installed and establishes a WWW proxy on TCP port 2282. Additionally, Sobig.f is reported to change the port of the Wingate WWW proxy to 3382. | |
David Tulo | 2004-04-29 16:04:40 |
There is a proxy or trojan scanner hitting TCP ports 80, 2282, 3128, 3382, 6588, 8000, 8080, and 22788. |
CVE # | Description |
---|