WORM: Conficker.C Activity

This signature detects traffic sent by the C variant of the Conficker/Downadup worm. The source address of the session may be infected with the worm and should be checked. Blocking using this signature has no effect in mitigating the spread of this worm. This signature can false positive on some Web browsers. To reduce the chance of false positives, it is recommended you apply this signature on outbound traffic going to the Internet and not on inbound traffic coming from the Internet.

Short Name
WORM:CONFICKER:C-ACTIVITY
Severity
Info
Recommended
False
Recommended Action
None
Category
WORM
Keywords
Activity Conficker.C
Release Date
03/30/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Rarely

Found a potential security threat?