A new Trojan that has been making its way around the Internet in recent weeks continues to baffle security experts, who have been unable to get a good handle on its behavior. The Trojan apparently made its first appearance around May 16 and began randomly scanning Internet-connected machines. The scanning was slow at first but has begun to pick up speed in recent days as more machines have become infected. Researchers at Internet Security Systems Inc. in Atlanta have been seeing nearly 3,000 scans an hour on Tuesday across the entire address space that the company monitors. The Trojan scans random ports on random machines, each time sending an initial SYN packet. One of the few identifiable characteristics of the program is a window size of 55808 on each of the packets it transmits. It also spoofs the originating IP address on all of the packets, making them look as if they’re coming from machines in unallocated name space. ISS has been tracking the Trojan for about a month and has yet to find a copy of its code or successfully trace it back to an infected machine. Other security vendors and officials at the Department of Homeland Security are also tracking the Trojan, all without any luck so far. Full Story
About OODA Analyst
OODA is comprised of a unique team of international experts capable of providing advanced intelligence and analysis, strategy and planning support, risk and threat management, training, decision support, crisis response, and security services to global corporations and governments.