![]() |
|
|
|
|
|||||||
| Forums | Portal | Register | Forum Rules | FAQ | Contribute | Members List | Arcade | Search | Today's Posts | Mark Forums Read |
| Malware Advisories (RSS) Malware Security Advisories Via RSS |
|
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Worm_ircbot.akz | iBot | Malware Advisories (RSS) | 0 | 01-25-2008 09:30 PM |
| Worm_ircbot.sn | iBot | Malware Advisories (RSS) | 0 | 01-22-2008 08:30 PM |
| Worm_ircbot.aqm | iBot | Malware Advisories (RSS) | 0 | 01-21-2008 12:10 PM |
| Worm_ircbot.el | iBot | Malware Advisories (RSS) | 0 | 01-04-2008 07:30 AM |
| Worm_ircbot.arb | iBot | Malware Advisories (RSS) | 0 | 12-27-2007 09:30 PM |
|
|
Submit Tools | LinkBack | Thread Tools | Display Modes |
|
||||
|
Worm_ircbot.mac
This worm may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself. It registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating registry keys/entries. It searches the network for certain shares, into which it attempts to drop copies of itself. It uses a list of user names and passwords to access password-protected shares. It connects to a certain Web site to send and receive information. It opens a random port to allow a remote user to connect to the affected system. Once a successful connection is established, the remote user executes commands on the affected system. More... |
||||
| Google The UNIX and Linux Forums |
| Forum Sponsor | ||
|
|