Port 3786 Details
known port assignments and vulnerabilities
threat/application/port search:
Port(s) |
Protocol |
Service |
Details |
Source |
3786 |
tcp,udp |
upstriggervsw |
Backdoor.Win32.VB.awm / Authentication Bypass - Information Leakage - тhe "Cryptech Heat" malware listens on TCP port 3786 and has an option to set an remote access password. The malware also runs a keylogger, we see imports for GetAsyncKeyState, GetKeyState, keybd_event and GetActiveWindow modules. Third-party attackers connecting to the infected system can use any password and will essentially see anything the victim types, searches or programs they run. As all information is piped out to whatever remote endpoint is connected.
References: [MVID-2021-0339]
VSW Upstrigger port (IANA official)
|
SG
|
3786 |
tcp,udp |
upstriggervsw |
VSW Upstrigger port, registered 2003-07 |
IANA
|
|
2 records found
|