Trojan.Kaht

Risk Level 1: Very Low

Discovered:
May 5, 2003
Updated:
February 13, 2007 12:00:57 PM
Also Known As:
TROJ_Kaht.A[Trend]
Type:
Trojan Horse
Systems Affected:
Microsoft IIS

Trojan.Kaht is a Hacktool used by its creator to scan for and exploit the vulnerability of the Microsoft WebDAV server, running IIS 5.0. An individual who successfully exploits this vulnerability may completely control an affected Web server.

Many applications use the vulnerable Win32 API component, ntdll.dll, so other attack vectors may exist. Symantec Security Response strongly recommends that all the users of Microsoft 2000 and NT 4.0 audit their computers for the vulnerabilities, which are referred to in the Microsoft Security Bulletin MS03-007.

Antivirus Protection Dates

  • Initial Rapid Release version May 5, 2003
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version May 5, 2003
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date May 7, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: Low
Writeup By: Yana Liu

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver