Loading...
[get complete service list]
Port Information
Protocol Service Name
tcp ssc-agent Symantec System Center
udp ssc-agent Symantec System Center
Top IPs Scanning
Today Yesterday
101.6.21.12 (6)143.42.1.201 (58)
64.39.106.86 (4)45.135.232.96 (29)
45.135.232.96 (4)139.144.239.78 (28)
103.133.110.12 (4)45.79.82.114 (20)
213.52.130.200 (4)45.79.109.130 (18)
172.161.106.93 (3)69.164.214.243 (18)
51.136.33.5 (3)45.79.109.4 (17)
104.45.12.40 (2)45.79.104.47 (17)
18.116.198.167 (2)45.33.84.124 (16)
104.46.39.174 (2)45.79.98.252 (16)
Port diary mentions
URL
SAV Worm Update
Good Morning 2007
Significant increase in port 2967 traffic
User Comments
Submitted By Date
Comment
Joe Kluwecksinski 2009-10-04 18:45:22
Recent tcp 2967 traffic appears to be related to an IRC BOT mostly aimed at colleges, but others, too. This link gives a rather good explanation of the exploit http://asert.arbornetworks.com/2006/11/that-new-bot-irc-bot-attacking-symantec-overflow/ Helpful hints: Look in C/windows for w32svc.exe. That's a bad thing if you have it. Also, look in services for "Windows Network Firewall", another bad thing.
CJ 2008-04-29 18:23:10
Did anyone notice the heaviest target numbers on this port is nearly always around the 1st and the 15th?
2008-04-29 18:22:39
Exploits an overflow condition in Symantec AV Corp. Masquerades as msupdates.exe, nod33.exe and wauclt.exe. Bot also connects back to an IRC server on a non-standard port. Lives in %windir%\system32 and is set as hidden and read only. Makes many registry changes to the netbt hive under HKLM\System\CurrentControlSet\Services and to the HKLM\SOFTWARE\Microsoft\Windows run and OLE keys. Runs IP scans en mass to discover other hosts to infect.
CVE Links
CVE # Description