Skip to main content
Skip to main content
Published Nov 27, 2006 | Updated Sep 15, 2017

Backdoor:Win32/Graweg.B!CME-762

Detected by Microsoft Defender Antivirus

Aliases: IRC-Mocbot!MS06-040 (McAfee) W32.Wargbot (Symantec) WORM_IRCBOT.JK (Trend Micro) W32/Cuebot-M (Sophos)

Summary

Update: This threat has been renamed Backdoor:Win32/Mocbot.A.
 
Backdoor:Win32/Graweg.B is an IRC Trojan that connects to an IRC channel and awaits commands from remote attackers. When instructed, Backdoor:Win32/Graweg.B begins searching the local network for systems which have not yet applied the Microsoft Windows Server Service security patch described in Microsoft Security Bulletin MS06-040. The Trojan also includes the ability to send messages via AOL Instant Messenger (AIM) and ICQ. The exploit code used by Backdoor:Win32/Graweg.B is only effective against un-patched systems running Windows 2000. However, the Trojan can still infect patched versions of Windows 2000 and other Windows operating systems by means other than exploit. For example, Backdoor:Win32/Graweg.B could be distributed as an e-mail attachment, or a link to the Trojan could be sent to e-mail or AIM recipients.
 
Backdoor:Win32/Graweg.B may lower security settings on infected systems and allows the system to be used for nefarious purposes, such as launching a Denial of Service (DoS) attack against others. Backdoor:Win32/Graweg.B includes the ability to download other files, thus the Trojan could update its functionality or download additional malicious software to infected systems.
 
Backdoor:Win32/Graweg.B has been assigned CME ID 762 and will be detected by Microsoft as
Backdoor:Win32/Graweg.B!CME-762.
Follow us