Event ID - 1115

Port No1115
Service NameLurker
RFC Doc0
ProtocolTCP
DescriptionThis application is a Remote Administration Tool (RAT), a Trojan that provides an intruder with the ability to remotely control a computer via a client on the intruder's machine and a “server" on the victim's machine. Often the intruder simply e-mails the RAT to the user along with a message that convinces the user to run the application. Lurker is a basic Chinese-language RAT. It requires an intruder to issue commands through a text-based command prompt rather than a Graphical User Interface (GUI). Lurker’s specific effects are unknown.
Reference LinkMore Information
AttackName:Lurker

1. Kill the following processes:
lcc.exe,
lurker.exe,
hehe.exe

2. Remove the following files
lcc.exe,
lurker.exe,
readme.txt.
hehe.exe in Windows

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.