WORM: Dabber TFTP File Transfer

This signature detects attempts by the Dabber worm to transfer itself to a target computer using TFTP. The Dabber worm infects targets already infected by the Sasser worm; this signature detects Dabber's fourth stage infection process. If this signature is detected in your network traffic, the target computer is infected with the Dabber worm and the attacking (requesting) computer is most likely infected with both the Sasser and Dabber worms.

Extended Description

WORM_DABBER.A is a worm that exploits a vulnerability in the FTP server component of Sasser worm. It opens a backdoor, modifies the Windows registry, and installs a TFTP server on a target system.

Short Name
WORM:DABBER:TFTP-TRANSFER
Severity
Major
Recommended
False
Recommended Action
Drop
Category
WORM
Keywords
Dabber File TFTP Transfer
Release Date
05/19/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?