WORM: MSN Chod.B

This signature detects the propagation of the CHOD.B worm binary over an MSN connections or similar protocols. For maximum protection, you should bind this signature to all high ports (1050-7000).

Extended Description

The Chod.B worm could allow a remote attacker to steal sensitive data from a victim machine, run malicious commands, and perhaps take full control of the machine. This worm could also cause denial of service conditions on the machine and on the network.

Short Name
WORM:CHOD.B
Severity
Minor
Recommended
False
Recommended Action
None
Category
WORM
Keywords
Chod.B MSN
Release Date
04/19/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/1094,6891-6900
False Positive
Unknown

Found a potential security threat?