Preface: UDP Trojan Horse probeLogo -Internet Security Systems

UDP Trojan Horse probe

advICE :Intrusions : 2003501
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?
Summary

A hacker may be scanning your system to see if a particular Trojan Horse program is installed on your system. This scan is likely nothing to be worried about.

Details

This is one the most common scans that home users will see directed against their systems. The traditional hacker technique is to post Trojan Horse programs on the Internet in newsgroups, on websites, or within e-mail spam. The hackers then run 'bots (robots) that scan huge portions of the Internet in order to see who has been infected with their programs.

Since any individual scanner is probing millions of potential victims, the likelihood is that the average user will get scanned every so often. However, most hackers want to compromise machines with fast, 24-hour connections like cable modems and DSL. Therefore, they target well-known address ranges, like 24.x.x.x, that support these high speed connections.

The most common UDP-based trojan horses detected by the intrusion-detection engine are listed below.
,
UDP portTrojan horse name
2140DeepThroat
3149Master's Paradise
10067Portal of Doom
31337Back Orifice (default port)
31789Hack'a'Tack
54321Back Orifice 2000 (default port)

False Positives

This will sometimes trigger when a hacker is scanning random ports on a machine. In this case, it is still probably a hostile act, but not necessarily against the specific Trojan Horse.

 more information
advICE: Trojan Horse  
These pages describe Trojan Horses, including lists of common ones seen in the wild.  
advICE: RATs  
The "Remote Access Trojan (RAT)" is the most common type of trojan that gives a hacker full control over the victim's machine. This section discusses popular RATs such as NetBus, Sub 7, and Back Orifice.  

 parametric information
portThe UDP port being probed
trojanThe name of the Trojan Horse program
reasonThe reason for the port probe.
Firewalledthe incoming UDP frame was stopped by the firewall.
ICMPsentan ICMP unreachable port frame was sent by the destination

 
Version appeared: 2.5 

Privacy Policy |  Copyright Info