numenmail.com

Monday, July 28, 2008

DoS.Perl.Vqserver

Aliases
DoS.Perl.Vqserver (Kaspersky Lab) is also known as: UNIX (McAfee), Hacktool.DoS (Symantec), Troj/VFtp-A (Sophos), DoS:PERL/Vqserver.A* (RAV), Unix/Vqserv@expl (FRISK), UNIX:Malware (ALWIL)

Technical details
This malicious program can be used to conduct a DoS attack on a remote server. It is a script file, written in Perl. The infected file is 744 bytes in size.

Payload
This script establishes a connection to port 80 on the HTTP vqServer 1.4.49. The remote malicious user gives the name of the server to be attacked.

A specially crafted HTTP GET command containing a string of 65000 'A's is then sent to the server. As a result of processing this command, the system under attack will crash.

Removal instructions
1. Delete the infected script file.
2. Update your antivirus databases and perform a full scan of the computer (download a trial version).

No comments: