SPYWARE: CrashCool 1-1

This signature detects the runtime behavior of spyware CrashCool. This spyware enables remotes attackers to connect to an infected host and execute commands. It also captures screenshots and logs keystrokes on the infected host.

Short Name
SPYWARE:TROJAN:CRASHCOOL-1-1
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SPYWARE
Keywords
1-1 CrashCool
Release Date
04/15/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/7777
False Positive
Unknown

Found a potential security threat?