Malware Payload Code Detection

critical Nessus Network Monitor Plugin ID 4471

Synopsis

The remote service appears to be distributing the payload of malware code.

Description

The remote port seems to be sending the payload of a malware. This is used by malware when spreading by infecting other hosts. The system is probably infected by a worm or a Trojan horse.

Solution

Inspect the system for malicious code and follow appropriate incident response procedures.

See Also

http://en.wikipedia.org/wiki/Storm_worm#Botnetting

Plugin Details

Severity: Critical

ID: 4471

Family: Backdoors

Published: 4/16/2008

Updated: 1/15/2016

Nessus ID: 31854