Endpoint Protection

 View Only
  • 1.  Dark Comet RAT ACtivity

    Posted Sep 19, 2013 05:30 PM

    Symantec is currently popping up with the following message:

    [SID:26653] System Infected: Dark Comet RAT Activity detected.

    Every time it fades away, it comes right back up.

    Does anyone here have experience in removing this risk?



  • 2.  RE: Dark Comet RAT ACtivity

    Posted Sep 19, 2013 05:39 PM

    Is the attack being blocked? If so, does it show the source in the security log?

    Symantec also has an AV signature for it so you should run a ful lscan in safe mode with latest defs

    https://www-secure.symantec.com/connect/blogs/darkcomet-rat-it-end



  • 3.  RE: Dark Comet RAT ACtivity

    Posted Feb 22, 2014 05:53 AM

    Having the Same Issue right now. It´s getting Blocked and i can see the Source IP. But what should i do with that?



  • 4.  RE: Dark Comet RAT ACtivity

    Posted Feb 22, 2014 08:00 AM

    You can put in a firewall rule to block the source IP.