| |
Lenny Zeltser - Reverse-Engineering Malware |
 | | A variant of the srvcp.exe trojan, discussed in this document, was brought to the attention of the defense community by Jeremy L. Gaddis on 8 June 2000. |
 | | In his posting to the Incidents mailing list, Jeremy reported noticing inbound connection attempts to TCP port 113 from an unknown host on the Internet, as well as unauthorized outbound connection attempts to a remote server on destination TCP port 6667. |
 | | This was critically helpful for our research, since the executable posted to the mailing list in the beginning of the thread turned out to be a benign copy of what seemed to be a Windows screen saver. |
| www.zeltser.com /reverse-malware-paper (10399 words) |