TROJAN: Subseven (HTTP)

This signature detects the runtime behavior of the Trojan Subseven, a remote administration tool. When remote attackers know the targe's IP address, they can gain complete control over it, including deleting files, adding files, killing processes, scanning screens, recording activities, extracting passwords and so on.

Extended Description

Subseven is a well-known Trojan with a backdoor capabilities. It enables remote attackers to gain full control over an infected machine without the knowledge of the victim.

Short Name
TROJAN:SUBSEVEN:SUBSEVEN-HTTP
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
TROJAN
Keywords
(HTTP) CVE-1999-0660 Subseven
Release Date
06/03/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown
CVSS Score

8.8

Found a potential security threat?