port scanner report

              G-Lock Software \ Products \ AATools \ Report examples\ Port Scanner Report


  AATools Port scanner detects active ports on the target machine and then it displays some kind of ad-hoc list of port assignments, some of which are registered assignments, some of which are unregistered uses, and some of which are just guesses about whether a port might be used by a Trojan.

Port Description/Possible Trojan simply shows what trojans and programs are known to commonly use a particular port. For example, a port description on port 25 shows this: SMTP - Simple Mail Transfer Protocol, RATs: Ajan, Antigen, Email Password Sender - EPS, EPS II, Gip, Gris, Happy99, Hpteam mail, I love you, Kuang2, Magic Horse, MBT (Mail Bombing Trojan), Moscow Email trojan, Naebi, NewApt worm, ProMail trojan, Shtirlitz, Stealth, Tapiras, Terminator, WinPC, WinSpy. That doesn't mean that you're infected with all of those trojans! It just lets you know which trojans and programs have been known to frequent that port.

If you are dealing with the port scan of a networked Windows machine, you are more than likely to find active ports in the 1024 - 5000 range, and this activity is nothing more than a Windows service or a Windows application using the vacant port for some legitimate function or another. (I think that most of these functions have to do with drive-mapping and file sharing services, but I'm not sure.)   Also it may be ICQ ports.

According to the official RFC, dynamic allocations are technically supposed to be used only in the very high port ranges, but it seems that Microsoft has decided instead to use the mid-range values of 1024 ... 5000 for this purpose. (The Microsoft dynamic allocation routine only allocates a port if it is not already active, therefore it doesn't ever interfere with, or clobber, any existing services that may be legitimately running in that range). So if you run the Port Scanner against a Windows machine and find activity on, say, "Port 1042 -- Bla 1.1 Trojan" do not be so alarmed. Port 1042 often turns out to be one of the ports that a Windows server will dynamically use to manage its resources.

For information about well known trojan programs, please go to our web page at http://www.glocksoft.com/trojan_port.htm

Below is example of HTML report produced by the AATools Port Scanner utility


Host IP Host Name Port Protocol Banner /Replises info Description Possible Trojan
             
192.168.0.1 My Computer 47624 UDP   Direct Play Server  
192.168.0.1 My Computer 47624 TCP   Direct Play Server  
192.168.0.1 My Computer 3456 UDP   VAT default data Terror trojan
192.168.0.1 My Computer 3008 UDP   Midnight Technologies  
192.168.0.1 My Computer 3001 UDP   Redwood Broker  
192.168.0.1 My Computer 3004 TCP   Csoft Agent  
192.168.0.1 My Computer 3003 TCP   CGMS  
192.168.0.1 My Computer 3002 TCP   RemoteWare Server/EXLM Agent  
192.168.0.1 My Computer 2020 TCP      
192.168.0.1 My Computer 1720 TCP   h323hostcall  
192.168.0.1 My Computer 500 UDP   isakmp  
192.168.0.1 My Computer 1025 TCP   network blackjack Remote Storm
192.168.0.1 My Computer 445 UDP   Microsoft-DS  
192.168.0.1 My Computer 138 UDP   NETBIOS Datagram Service Chode
192.168.0.1 My Computer 161 UDP   SNMP  
192.168.0.1 My Computer 137 UDP   NETBIOS Name Service Chode, (UDP) - Msinit
192.168.0.1 My Computer 445 TCP   Microsoft-DS  
192.168.0.1 My Computer 443 TCP   http protocol over TLS/SSL  
192.168.0.1 My Computer 68 UDP   Bootstrap Protocol Client  
192.168.0.1 My Computer 53 UDP   Domain Name Server  
192.168.0.1 My Computer 67 UDP   Bootstrap Protocol Server  
192.168.0.1 My Computer 139 TCP   NETBIOS Session Service Chode, God Message worm, Msinit, Netlog, Network, Qaz
192.168.0.1 My Computer 135 TCP   DCE endpoint resolution  
192.168.0.1 My Computer 80 TCP Server: Microsoft-IIS/5.0 World Wide Web HTTP 711 trojan (Seven Eleven), AckCmd, Back End, Back Orifice 2000 Plug-Ins, Cafeini, CGI Backdoor, Executor, God Message, God Message Creator, Hooker, IISworm, MTX, NCX, Reverse WWW Tunnel Backdoor, RingZero, Seeker, WAN Remote, Web Server CT, WebDownloader
192.168.0.1 My Computer 25 TCP 220 Advanced ESMTP is Ready Simple Mail Transfer Ajan, Antigen, Barok, Email Password Sender - EPS, EPS II, Gip, Gris, Happy99, Hpteam mail, Hybris, I love you, Kuang2, Magic Horse, MBT (Mail Bombing Trojan), Moscow Email trojan, Naebi, NewApt worm, ProMail trojan, Shtirlitz, Stealth, Tapiras, Terminator, WinPC, WinSpy
192.168.0.1 My Computer 21 TCP 220 My Computer Microsoft FTP Service (Version 5.0). File Transfer [Control] Back Construction, Blade Runner, Cattivik FTP Server, CC Invader, Dark FTP, Doly Trojan, Fore, Invisible FTP, Juggernaut 42, Larva, MotIv FTP, Net Administrator, Ramen, Senna Spy FTP server, The Flu, Traitor 21, WebEx, WinCrash
192.168.0.1 My Computer   ICMP Received 56 bytes in 0 msecs    

 (C) Advanced Administrative Tools