WORM: Conficker.C Activity (2)

This signature detects traffic sent by the C variant of the Conficker/Downadup worm. The source address of the session may be infected with the worm and should be checked. Blocking using this signature has little effect in mitigating the spread of this worm. This signature may false positive on some Web browsers. To reduce the chance of false positives, it is recommended you apply this signature on outbound traffic going to the Internet and not on inbound traffic coming from the Internet.

Short Name
WORM:CONFICKER:C-ACTIVITY-2
Severity
Info
Recommended
False
Recommended Action
None
Category
WORM
Keywords
(2) Activity Conficker.C
Release Date
03/30/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Rarely

Found a potential security threat?