Short Name |
WORM:SDBOT:DX-IRC-BEACON |
---|---|
Severity |
Critical |
Recommended |
No |
Recommended Action |
Drop |
Category |
WORM |
Release Date |
2004/04/14 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects the DX variant of the SDBot Worm/Trojan connecting to an IRC server (to report that the Trojan is available). Because this activity indicates that the sending host is infected, you should take appropriate security measures immediately.
SDBot-DX is a worm that infects Windows operating systems. It attempts to spread through Windows default administrative shares.