Event ID - 49301

Port No49301
Service NameOnLine KeyLogger
RFC Doc0
ProtocolTCP
DescriptionWorks on Windows. Telnet is used as client.
Reference LinkOnLine_KeyLogger
AttackRegisters:
HLM\Software\Microsoft\Windows\CurrentVersion\RunServi ces

Files:
System.sys - - 19,813 bytes

Actions:
Keylogger
This trojan sends everything typed online using port 49301. Copies send to the hard drive are set as Temp.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.