TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
PERL_SANTY.D
Overview

Malware type: Worm

Aliases: Net-Worm.Perl.Spyki.c (Kaspersky), Exploit-phpBB!hilight (McAfee), Perl.Santy.C (Symantec), PERL/Spyki.c (Avira), Perl/Santy-Fam (Sophos),

In the wild: Yes

Destructive: No

Language: English

Platform: Unix

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

This malware takes advantage of the PHPBB Remote URLDecode Input Validation Vulnerability to obtain access to remote Web servers.

It attempts to download scripts from a specified location and execute them in an infected system. It then uses the America Online (AOL) and Yahoo search engines to search for the string viewtopic.php, to be able to generate a list of possible infection targets.

It also attempts to delete certain files from the infected hosts.

This worm runs on Unix platforms.

For additional information about this threat, see:
Solution
Technical Details

Description created: Dec. 27, 2004 1:10:37 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.