TROJAN: Phoenix Initial Server Response

This signature detects the initial server response from a Phoenix backdoor Trojan. Detecting this response indicates that your system is infected with the Phoenix backdoor Trojan. Using the Phoenix client, attackers can gain unauthorized access to the host computer and execute malicious operations.

Extended Description

Phoenix is a remote administration tool. It enables remote attackers to control an infected machine.

Short Name
TROJAN:MISC:PHOENIX-SERV-RESP
Severity
Major
Recommended
False
Recommended Action
Drop
Category
TROJAN
Keywords
CVE-1999-0660 Initial Phoenix Response Server
Release Date
01/09/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/7410
False Positive
Unknown
CVSS Score

8.8

Found a potential security threat?