Looked.P
Also being called Trojan.PWS.Gamania.origin, Trojan-PSW.Win32.OnLineGames.aenl, Trojan-PSW.Win32.OnLineGames.aenl, Win32.Looked.P(v)
Samples involved:
7bbec6c1d7d727e70854184b1c1c5088
6720556aa97632ae3d3bd7f88f6c572f
CnC? on ports 81, 83 seen. Client sends:
6 bytes
#108/!
Several times, eventually receives
6 bytes
#109/!
Sigs
2008219 and
2008220 will detect.
--
MattJonkman - 14 May 2008