📄 141.txt
字号:
Rule:--Sid:141--Summary:hack-a-tack is a Trojan Horse.--Impact:Possible theft of data via download, upload of files, execution of files and reboot the targeted machine.--Detailed Information:The Trojan changes system registry settings to add the hack-a-tack server to programs normally started on boot. Due to the nature of this Trojan it is unlikely that the attacker's client IP address has been spoofed. SID Message --- ------- 141 HackAttack 1.20 Connect 614 hack-a-tack attemptThis Trojan is commonly used to install other Trojan programs.The server portion opens TCP ports 31785 and 31787 and UDP ports 31789 and 31791 by default to establish a connection between client and server. The ports may then be configured by the attacker to use something other than these defaults.--Affected Systems: Windows 95 Windows 98 Windows ME Windows NT Windows 2000 Windows XP--Attack Scenarios:This Trojan may be delivered to the target in a number of ways. This event is indicative of an existing infection being activated. Initial compromise can be in the form of a Win32 installation program that may use the extension ".jpg" or ".bmp" when delivered via e-mail for example.--Ease of Attack:This is Trojan activity, the target machine may already be compromised. Updated virus definition files are essential in detecting this Trojan.The Trojan server is located at <drive>:\WINDOWS\Expl32.exe.--False Positives:None Known--False Negatives:None Known--Corrective Action:Edit the system registry to remove the extra keys or restore a previously known good copy of the registry.Affected registry keys are: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Registry keys added are: Explorer32 ="<drive>:\windows\Expl32.exe" Configuration Wizard = "<drive>:\windows=cfgwiz32.exe"Removal of this entry is required.Delete the file(s) <drive>:\WINDOWS\Expl32.exe and <drive>:\windows=cfgwiz32.exeEnding the Trojan process is also necessary. A reboot of the infected machine is recommended.--Contributors:Original Rule Writer Max Vision <vision@whitehats.com>Sourcefire Research TeamNigel Houghton <nigel.houghton@sourcefire.com>--Additional References:Whitehats arachNIDShttp://www.whitehats.com/info/IDS314http://www.whitehats.com/info/IDS504Hackfix.orghttp://www.hackfix.org/miscfix/hackatack.shtmlCommodon Communicationshttp://www.commodon.com/threat/threat-hack.htm--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -