Event ID - 12624

Port No12624
Service NameButtMan
RFC Doc0
ProtocolTCP
DescriptionButtMan is a RAT. Once installed, ButtMan server version 0.9n adds the registry key: Whatever the filename is to ensure that it runs whenever the system starts. By default, ButtMan server v09.n listens on Transmission Control Protocol (TCP) port 12624
Reference LinkJ-Security Center

More Information
AttackName:Buttman

.

A ButtMan server, once installed, opens a backdoor and enables remote attackers to perform malicious actions including:
1. Capture screenshots
2. Chat
3. Manage the filesystem
4. E-mail notification
5. Log keys
6. Obtain system information
7. Edit the registry

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.