Analysis by: Homer Pacag

ALIASES:

Application.Fscan.A (F-Secure); W32/HackTool.VG (F-Prot)

 PLATFORM:

Linux OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Hacking Tool

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This is a Fast SYN Scanner that uses libnet and libpcap, which require root level access. It scans a given netblock on a specified port, using the specified interface with some type of speed setting value.

A certain command may be used in this tool. It is a port scanning command line tool. that scans open ports to the target IP address.

This hacking tool hacks a computer by running a command line.

  TECHNICAL DETAILS

File Size: 13,312 bytes
File Type: ELF
Memory Resident: No

Hacktool Routine

This hacking tool hacks a computer by running a command line.

  SOLUTION

Minimum Scan Engine: 8.900
SSAPI PATTERN File: 1.164.28
SSAPI PATTERN Date: 07 Apr 2011

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.

Step 2

Scan your computer with your Trend Micro product to delete files detected as HACKINGTOOLS_FSCAN. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.


Did this description help? Tell us how we did.