We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Wootbot
Detected by Microsoft Defender Antivirus
Aliases: W32.Spybot.Worm (Symantec) WORM_FORBOT (Trend Micro) WORM_WOOTBOT (Trend Micro) W32/Sdbot.worm (McAfee) Backdoor.Win32.Wootbot (Kaspersky)
Summary
Backdoor:Win32/Wootbot is a backdoor Trojan that targets certain versions of Microsoft Windows. The Trojan connects to a specific IRC server to receive commands from attackers, which can include instructions to spread to other computers in various ways, such as through network shares, SQL servers, and exploitation of certain Windows vulnerabilities.