WORM: Witty Infection Attempt

This signature detects the Witty worm attempting to infect a new host. Some ISS BlackIce ICQ decoder versions contain a vulnerability that Witty exploits to propagate from host to host. The worm corrupts local data, consumes network resources, and propagates itself.

Extended Description

The W32.Witty.Worm can cause data loss and system failure on an infected machine.

Short Name
WORM:WITTY:INFECT-ATTEMPT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
WORM
Keywords
Attempt Infection Witty
Release Date
03/25/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3538
Port
UDP/0-52,54-66,70-122,124,136,140-160,163-388,390-635,637-65535
False Positive
Unknown

Found a potential security threat?