TFTP: GET Admin.dll File

This signature detects attempts to uses TFTP to access the admin.dll file in the root directory. This can indicate the presence of the Nimda worm on the system.

Extended Description

The Nimda worm enables file sharing and creates an administrative account on and infected machine.

Short Name
TFTP:FILE:ADMIN-DLL
Severity
Minor
Recommended
False
Recommended Action
None
Category
TFTP
Keywords
Admin.dll File GET
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?