IDP Signatures

61577 BACKDOOR.DoomJuice.File.Upload.Attempt

Back to list
Signature Id 61577
Name BACKDOOR.DoomJuice.File.Upload.Attempt
Group IDS WORM GENERAL
Issued 2008-11-04
Last Updated 2010-12-01
Description This event is indicative of activity by the Doom Juice worm. This worm attempts to connect to random addresses on port 3127, and upon a response, will attempt to upload a copy of itself to the target machine. If no response is received on that port, it will try other ports between 3127 and 3199. If the date is between February 8th and February 28th 2004, the worm will attempt to launch a Denial of Service (DoS) attack against www.microsoft.com.