Port 3119 Details
known port assignments and vulnerabilities
threat/application/port search:
Port(s) |
Protocol |
Service |
Details |
Source |
3119 |
tcp,udp |
d2000kernel |
Trojans using this port: Delta Remote Access
Backdoor.Win32.DRA.c / Weak Hardcoded Password - the malware listens on TCP port 3119 and authentication is required. However, the password "go" is weak and hardcoded in the PE file. The malware uses "lstrcmpa" Win32 API to check the password, when sending the password we need to be careful that there is no line feed "\n" E.g. "go\n", as what happens when sent using ncat or telnet causing authentication to fail.
References: [MVID-2022-0470]
IANA registered for: D2000 Kernel Port |
SG
|
3119 |
tcp |
trojan |
Delta Remote Access |
Trojans
|
3119 |
tcp,udp |
d2000kernel |
D2000 Kernel Port |
IANA
|
3074-3174 |
udp |
applications |
Rainbow Six Vegas |
Portforward
|
|
4 records found
Related ports: 3120
|