Port Details - Port 2967

Oct 24 135 Oct 25 155 Oct 26 154 Oct 27 155 Oct 28 140 Oct 29 141 Oct 30 154 Oct 31 164 Nov 01 334 Nov 02 397 Nov 03 326 Nov 04 186 Nov 05 175 Nov 06 197 Nov 07 165 Nov 08 159 Nov 09 203 Nov 10 150 Nov 11 94 Nov 12 105 Nov 13 106 Nov 14 146 Nov 15 185 Nov 16 159 Nov 17 271 Nov 18 104 Nov 19 153 Nov 20 1,735 Nov 21 858 Nov 22 40 Oct 24 60,073 Oct 25 78,905 Oct 26 67,011 Oct 27 28,499 Oct 28 78,562 Oct 29 77,156 Oct 30 80,146 Oct 31 80,870 Nov 01 80,309 Nov 02 81,263 Nov 03 81,816 Nov 04 75,665 Nov 05 15,686 Nov 06 80,105 Nov 07 81,073 Nov 08 78,699 Nov 09 77,568 Nov 10 68,964 Nov 11 75,759 Nov 12 15,124 Nov 13 57,202 Nov 14 59,641 Nov 15 62,075 Nov 16 74,575 Nov 17 80,066 Nov 18 71,424 Nov 19 78,942 Nov 20 81,260 Nov 21 80,645 Nov 22 8,598
[show ascii data]
  • Start Date:
  • End Date:
  • Port:
  • Left Graph:
  • Right Graph:
  • Show Range:Yes No

Port Information

ProtocolServiceName
tcpssc-agentSymantec System Center
udpssc-agentSymantec System Center
[get complete service list]

User Comment

Submitted ByDate
Comment
Joe Kluwecksinski2009-10-04 18:45:22
Recent tcp 2967 traffic appears to be related to an IRC BOT mostly aimed at colleges, but others, too. This link gives a rather good explanation of the exploit http://asert.arbornetworks.com/2006/11/that-new-bot-irc-bot-attacking-symantec-overflow/ Helpful hints: Look in C/windows for w32svc.exe. That's a bad thing if you have it. Also, look in services for "Windows Network Firewall", another bad thing.
CJ2008-04-29 18:23:10
Did anyone notice the heaviest target numbers on this port is nearly always around the 1st and the 15th?
2008-04-29 18:22:39
Exploits an overflow condition in Symantec AV Corp. Masquerades as msupdates.exe, nod33.exe and wauclt.exe. Bot also connects back to an IRC server on a non-standard port. Lives in %windir%\system32 and is set as hidden and read only. Makes many registry changes to the netbt hive under HKLM\System\CurrentControlSet\Services and to the HKLM\SOFTWARE\Microsoft\Windows run and OLE keys. Runs IP scans en mass to discover other hosts to infect.
Add a comment

CVE Links

CVE #Description
CVE-2006-2630 "Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors."