TFTP: GET Admin.dll File
This signature detects attempts to uses TFTP to access the admin.dll file in the root directory. This can indicate the presence of the Nimda worm on the system.
Extended Description
The Nimda worm enables file sharing and creates an administrative account on and infected machine.
References
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3