SPYWARE: K-MsnRat 1.0.0

This signature detects the runtime behavior of the spyware K-MsnRat 1.0.0. This spyware is a reverse connecting Remote Administration Trojan (RAT). It allows an attacker to control a remote MSN messenger without the user's consent. It provides the remote attacker with the status of the MSN Messenger on the remote computer, which allows sending messages as the victim, changing nick names, and blocking contacts.

Short Name
SPYWARE:TROJAN:KMSNRAT100
Severity
Major
Recommended
False
Recommended Action
None
Category
SPYWARE
Keywords
1.0.0 K-MsnRat
Release Date
05/31/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/6789
False Positive
Unknown

Found a potential security threat?