TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_SDBOT.BZS
Overview

Malware type: Worm

Aliases: Backdoor.Win32.Rbot.gen (Kaspersky), W32/Sdbot.worm.gen.h (McAfee), W32.Spybot.Worm (Symantec), WORM/Rbot.Gen (Avira), W32/Rbot-Gen (Sophos),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 95, 98, ME, NT, 2000, XP

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

This worm spreads by dropping a copy of itself in the shared folder IPC$.

It also takes advantage of the Microsoft Windows Plug and Play vulnerability to propagate across networks. For more information regarding this vulnerability, please refer to the following Microsoft Web page:

This worm has backdoor capabilities. It opens a random port and acts as an Internet Relay Chat (IRC) bot, which connects to a remote IRC server. It then joins a specific IRC channel, where it listens for commands coming from a remote malicious user.

As part of its backdoor capabilities, this worm also performs distributed denial of service flood attacks.

For additional information about this threat, see:
Solution
Technical Details

Description created: Aug. 16, 2005 7:23:15 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.