TROJAN: Vampire Initial Server Response

This signature detects the initial server response from a Vampire backdoor Trojan. Attackers can use the Vampire Client to send commands to the infected machine, allowing them to gain full control and perform dangerous actions on this machine.

Extended Description

Vampire is a remote administration tool. It enables remote attackers to completely control an infected machine.

Short Name
TROJAN:MISC:VAMPIRE-SRV-RESP
Severity
Major
Recommended
False
Recommended Action
Drop
Category
TROJAN
Keywords
CVE-1999-0660 Initial Response Server Vampire
Release Date
01/14/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/1020,6669
False Positive
Unknown
CVSS Score

8.8

Found a potential security threat?