Microsoft Executable in Transit Detection

Critical Nessus Network Monitor Plugin ID 5701


The remote host may be compromised


This service appears to send a Microsoft Windows executable when a connection to it is established. This may be evidence of some malware which are known to propagate in this manner. There is not a file name associated with this executable. That is, the client created a TCP/IP connection to the host, at which time the host sent an executable back to the client. The PVS has determined that this is an Microsoft executable based upon the format of the binary.


Check the host and disinfect / reinstall it if necessary.

Plugin Details

Severity: Critical

ID: 5701

Family: Backdoors

Published: 2010/11/09

Modified: 2016/01/15

Risk Information

Risk Factor: Critical