lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: brent.colflesh at ulticom.com (Brent Colflesh)
Subject: Lots of traffic on port 1472 from explorer

Keylogger?
http://www.pestpatrol.com/pestinfo/k/klp32.asp

Regards,
Brent

-----Original Message-----
From: full-disclosure-admin@...ts.netsys.com
[mailto:full-disclosure-admin@...ts.netsys.com]On Behalf Of Giuseppe
Milicia
Sent: Tuesday, September 21, 2004 3:14 PM
To: full-disclosure@...ts.netsys.com
Subject: [Full-Disclosure] Lots of traffic on port 1472 from explorer


Hi guys,

from a home computer I'm seeing lots of traffic generated from
explorer on port 1472 towards the microsoft-ds port, typically
on IP addresses starting with 35.xx.xx.xx

It looks like a worm but I could not find any references around
and Trend Micro detects nothing.

Also there is some hidden process oakklp32.exe which is not shown
by the taskmanager but is costantly active, again I could not
find anything about it!

Ideas? Clues?

Thanks,

--
Giuseppe

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.762 / Virus Database: 510 - Release Date: 9/13/2004

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.762 / Virus Database: 510 - Release Date: 9/13/2004


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ