WORM: Lovegate Infected Host

This signature detects attempts to send e-mails messages to 54love@fescomail.net or hacker117@163.com. Attempted messages to these addresses indicate that the host is infected by the Lovegate Worm. An attacker can use the information from these messages to access the host and perform malicious actions.

Extended Description

Lovegate infects Microsoft Windows operating systems and propagates through e-mail attachments and shared folders. It also creates backdoors that allow attackers to control the affected host remotely. Once a system is successfully infected, it attempts to send e-mail notification of infection to a pair of email addresses.

Short Name
WORM:LOVEGATE-INFECTED
Severity
Major
Recommended
False
Recommended Action
Drop
Category
WORM
Keywords
Host Infected Lovegate
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?