SPYWARE: HTTPRat

This signature detects the runtime behavior of HTTPRat, a Trojan program. This spyware enables remote attackers to create the backdoor executable Zombam.B, which attempts to terminate antivirus and firewall processes running on the infected host. Remote attackers can then use a Web browser to access the infected host.

Short Name
SPYWARE:TROJAN:HTTPRAT
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
SPYWARE
Keywords
HTTPRat
Release Date
05/02/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?