Event ID - 911

Port No911
Service NameDark Shadow
RFC Doc0
ProtocolTCP
DescriptionWorks on Windows. Password = UHA. Compatible with the Back Orifice server.
Reference LinkDark Shadow Trojan
AttackIt autoloads the Registry:
HLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices \

File :
Darkshadow.zip - 87,119 bytes Darkshadow.trojan.exe - 180,321 bytes Winfunctions.exe -

It does the following :
Remote Access
The trojan is encrypted.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.