Discovered: September 4, 2003
Updated: September 5, 2003 9:23:49 PM
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows 2000
Backdoor.Coreflood.B is a remote access program installed by Backdoor.Coreflood.dr that is also capable of DDoS functions. Backdoor.Coreflood.B is a minor variant of Backdoor.Coreflood (MCID 1486).
The program is downloaded via the Backdoor.Coreflood.dr (MCID 1908) script, and executed on the compromised host.
When installed, the backdoor connects to an IRC server and gives control of the compromised computer to the hacker. The backdoor allows the attacker to perform various actions including conducting a DoS attack against an attacker specified third party.