Event ID - 1151

Port No1151
Service NameOrion
RFC Doc0
ProtocolTCP
DescriptionWorks on Windows 95, 98 and NT.
Reference Link
AttackFile :
Systray.exe - Undll.exe - - 27,136 bytes

It does the following :
Remote Access
Propagated as a serial generator for Fruity Loops Pro. When generating a new serial number, it installs Orion. Undll.exe is the trojan but packed with UPX v1.01.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.