Event ID - 23321

Port No23321
Service NameKonik
RFC Doc0
ProtocolTCP
DescriptionThis alert indicates that a remote user is trying to connect to a system in your network using the Konik Trojan Horse program. Trojan Horse programs enable remote users to gain access to data or system functions on systems where a Trojan Horse has been installed. A Trojan does not copy itself and spread further through file sharing or auto-emailing like a worm; rather, it is typically installed from an executable, such as an email attachment. Once installed, it allows a remote client to open a connection to the affected system. With this open connection, the remote client has access to certain functions on the affected host.
Reference LinkMore Information
AttackName:Konik

Infection with the Konik Trojan can give unauthorized system access to a remote attacker. Notably, the Konik Trojan is able to give someone full control of the trojaned system, including the ability to use the File Manager, the ability to View/Close processes, and the ability to reboot/shut down Windows

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.