Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: Significant increase on 38566 SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Significant increase on 38566

On this quiet Handler day I received an email from a reader questioning recent activity on 38566.  This port is used, according to TrendMicro as BKDR_TRODOR.A, which is a password-stealing backdoor.   The strange thing about this as compared to others we see is the number of sources versus the number of targets.  If anybody could submit some packet captures we'd love to take a look.


150 Posts
ISC Handler
May 6th 2006

Sign Up for Free or Log In to start participating in the conversation!