Short Name |
WORM:BAGLE:HTTP-BACKDOOR |
---|---|
Severity |
Critical |
Recommended |
No |
Recommended Action |
Drop |
Category |
WORM |
Keywords |
bagle worm backdoor |
Release Date |
2004/08/11 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects HTTP traffic from a backdoor created by the Bagle worm upon infection.
WORM_BAGLE.A is a worm that propagates via SMTP e-mails messages. It modifies the registry and opens a backdoor to enable remote attackers to control an infected machine.