WORM: SDBot.DX Infected Host IRC Beacon

This signature detects the DX variant of the SDBot Worm/Trojan connecting to an IRC server (to report that the Trojan is available). Because this activity indicates that the sending host is infected, you should take appropriate security measures immediately.

Extended Description

SDBot-DX is a worm that infects Windows operating systems. It attempts to spread through Windows default administrative shares.

Short Name
WORM:SDBOT:DX-IRC-BEACON
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
WORM
Keywords
Beacon Host IRC Infected SDBot.DX
Release Date
04/14/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/89
False Positive
Unknown

Found a potential security threat?