Trojan:Win32/Swrort.A is a detection for files that try to connect to a remote server. Once connected, an attacker can perform malicious routines such as downloading other files.
They can be installed from a malicious site or used as payloads of exploit files.
Once executed, Trojan:Win32/Swrort.A may connect to a remote server using different port numbers. Once connected, an attacker can perform malicious routines such as downloading other malware and executing them.
We have seen this threat connect to the following servers:
220.127.116.11 via TCP port 4444
10.10.10.31 via TCP port 443
18.104.22.168 via TCP port 1234
Analysis by Elda Dimakiling
Alerts from your security software may be the only symptom.