EC-Council
EC0-350 · Question #607
Jason's Web server was attacked by a trojan virus. He runs protocol analyzer and notices that the trojan communicates to a remote server on the Internet. Shown below is the standard "hexdump"…
The correct answer is D. Port 6667 (Net-Devil Trojan). See the full explanation below for the reasoning.
Question
Jason's Web server was attacked by a trojan virus. He runs protocol analyzer and notices that the trojan communicates to a remote server on the Internet. Shown below is the standard "hexdump" representation of the network packet, before being decoded. Jason wants to identify the trojan by looking at the destination port number and mapping to a trojan-port number database on the Internet. Identify the remote server's port number by decoding the packet?
Options
- APort 1890 (Net-Devil Trojan)
- BPort 1786 (Net-Devil Trojan)
- CPort 1909 (Net-Devil Trojan)
- DPort 6667 (Net-Devil Trojan)
How the community answered
(28 responses)- A7% (2)
- B11% (3)
- C4% (1)
- D79% (22)
Community Discussion
No community discussion yet for this question.