GCIH · Question #171
John works as a Network Administrator for We-are-secure Inc. He finds that TCP port 7597 of the Weare- secure server is open. He suspects that it may be open due to a Trojan installed on the server…
The correct answer is B. Qaz. The Qaz Trojan is uniquely identified by its behavior of renaming Notepad.exe to Note.com, replacing it with itself, and opening a backdoor on TCP port 7597.
Question
John works as a Network Administrator for We-are-secure Inc. He finds that TCP port 7597 of the Weare- secure server is open. He suspects that it may be open due to a Trojan installed on the server. He presents a report to the company describing the symptoms of the Trojan. A summary of the report is given below:
Once this Trojan has been installed on the computer, it searches Notpad.exe, renames it Note.com, and then copies itself to the computer as Notepad.exe. Each time Notepad.exe is executed, the Trojan executes and calls the original Notepad to avoid being noticed. Which of the following Trojans has the symptoms as the one described above?
Options
- ANetBus
- BQaz
- CeBlaster
- DSubSeven
How the community answered
(39 responses)- A3% (1)
- B87% (34)
- C3% (1)
- D8% (3)
Why each option
The Qaz Trojan is uniquely identified by its behavior of renaming Notepad.exe to Note.com, replacing it with itself, and opening a backdoor on TCP port 7597.
NetBus is a remote access Trojan that communicates on TCP ports 12345 and 12346 and does not perform the Notepad.exe hijacking or port 7597 behavior described.
Qaz is a documented backdoor Trojan that specifically targets the Windows Notepad application - it renames the legitimate notepad.exe to note.com and copies itself in its place so that every invocation of Notepad silently executes the Trojan before calling the real editor. It opens TCP port 7597 to allow remote access, matching every symptom described in the scenario.
eBlaster is commercial monitoring and spyware software used to log user activity - it does not rename or replace system executables like Notepad.exe and does not use port 7597.
SubSeven (Sub7) is a remote administration Trojan that typically operates on port 27374 and does not exhibit the Notepad.exe renaming and self-substitution behavior described in the scenario.
Concept tested: Qaz Trojan identification by behavior and port
Source: https://web.archive.org/web/20040208103915/http://www.symantec.com/avcenter/venc/data/trojan.qaz.html
Topics
Community Discussion
No community discussion yet for this question.