Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Significant increase on 38566 - SANS Internet Storm Center SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Significant increase on 38566

On this quiet Handler day I received an email from a reader questioning recent activity on 38566.  This port is used, according to TrendMicro as BKDR_TRODOR.A, which is a password-stealing backdoor.   The strange thing about this as compared to others we see is the number of sources versus the number of targets.  If anybody could submit some packet captures we'd love to take a look.

Tony

150 Posts
ISC Handler

Sign Up for Free or Log In to start participating in the conversation!