Event ID - 5889

Port No5889
Service NameY3KRAT
RFC Doc0
ProtocolTCP
DescriptionBackdoor Y3K RAT 1.1 is a Trojan that opens up a backdoor program that, once installed on a system, permits unauthorized users to remotely perform a variety of operations, such as changing the registry, executing commands, starting services, listing files, and uploading or downloading files. Y3K RAT typically runs from the server file "C:\WINDOWS\RundlI.exe" over ports 5882, 5888, and 5889 via TCP.
Reference LinkMore Inormation
AttackName:Y3KRAT

A Trojan is a program that enables an attacker to get nearly complete control over an infected PC. Frequently used by as a tool by malicious hackers. When this program executes, the program performs a specific set of actions. This usually works toward the goal of allowing the trojan to survive on a system and open up a backdoor

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.