Looked.P

Also being called Trojan.PWS.Gamania.origin, Trojan-PSW.Win32.OnLineGames.aenl, Trojan-PSW.Win32.OnLineGames.aenl, Win32.Looked.P(v)

Samples involved: 7bbec6c1d7d727e70854184b1c1c5088 6720556aa97632ae3d3bd7f88f6c572f

CnC? on ports 81, 83 seen. Client sends:

6 bytes

#108/!

Several times, eventually receives

6 bytes

#109/!

Sigs 2008219 and 2008220 will detect.

-- MattJonkman - 14 May 2008

Topic revision: r2 - 2008-07-11 - MattJonkman
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats