WORM: Akak Backdoor Activity
This signature detects Akak worm traffic over port 4321. The Akak worm typically infects targets by exploiting an Internet Explorer JavaScript vulnerability. After a target is infected, Akak enables malicious users to remotely control a Windows host.
Extended Description
Worm Akak is a backdoor program that creates a SOCKS proxy on a compromised system. It allows a remote attacker to download and execute files on the compromised computer.
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3