Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

WORM:SDBOT:DX-IRC-BEACON

Severity

Critical

Recommended

No

Recommended Action

Drop

Category

WORM

Release Date

2004/04/14

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

WORM: SDBot.DX Infected Host IRC Beacon


This signature detects the DX variant of the SDBot Worm/Trojan connecting to an IRC server (to report that the Trojan is available). Because this activity indicates that the sending host is infected, you should take appropriate security measures immediately.

Extended Description

SDBot-DX is a worm that infects Windows operating systems. It attempts to spread through Windows default administrative shares.

References

  • URL: http://vil.nai.com/vil/content/v_100454.htm
  • URL: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.y.html
  • URL: http://www.sophos.com/virusinfo/analyses/w32sdbotbc.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out