IDP Signatures
61577 BACKDOOR.DoomJuice.File.Upload.Attempt
Back to listSignature Id | 61577 |
Name | BACKDOOR.DoomJuice.File.Upload.Attempt |
Group | IDS WORM GENERAL |
Issued | 2008-11-04 |
Last Updated | 2010-12-01 |
Description | This event is indicative of activity by the Doom Juice worm. This worm attempts to connect to random addresses on port 3127, and upon a response, will attempt to upload a copy of itself to the target machine. If no response is received on that port, it will try other ports between 3127 and 3199. If the date is between February 8th and February 28th 2004, the worm will attempt to launch a Denial of Service (DoS) attack against www.microsoft.com. |