wileybot
12-06-00, 05:57 PM
below is a entry my firewall came up with! i am assuming that this was an outside attack (inbound) but when i looked this up on the web it says it installs itself in the windows registry and then attempts to contact the Hooligan. whats going on? is this on my sys. which i cant seem to find or an ext. attack?
Date: 12/05/2000 Time: 19:35:33
Rule "Default Block Backdoor/SubSeven Trojan" blocked (199.174.blah blah). Details:
Inbound TCP connection
Local address,service is (199.174.blah blah). Remote address,service is (63.15.111.blah blah).
Process name is "N/A"
Date: 12/05/2000 Time: 19:35:33
Rule "Default Block Backdoor/SubSeven Trojan" blocked (199.174.blah blah). Details:
Inbound TCP connection
Local address,service is (199.174.blah blah). Remote address,service is (63.15.111.blah blah).
Process name is "N/A"