Event ID - 2004

Port No2004
Service NameMailbox
RFC Doc0
ProtocolTCP
DescriptionThe purpose of a mail box protocol is to provide at each site a standard mechanism to receive sequential files for immediate or deferred printing or other uses. The files for deferred printing would probably be stored in intermediate disk files, although details of how a file is handled, stored, manipulated, or printed at a site are not the concern of this protocol.
Reference LinkMore Information
AttackName:Duddie

Backdoor Duddie is a Trojan that opens up a backdoor program that, once installed on a system, permits unauthorized users to remotely perform a variety of operations, such as changing the registry, executing commands, starting services, listing files, and uploading or downloading files. Duddie typically runs from the server file "C:\WINDOWS\WDBYLG.EXE" over port 2001 via TCP.

Duddie Trojan manual removal: 1. Kill processes:
duddiec.exe, duddies.exe, server .exe, config.exe, wbdylg.exe, winlog.exe

2. Delete files:
duddiec.exe, duddies.exe, server.exe, config.exe, wbdylg.exe, winlog.exe

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.