We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Win32/Esbot
Detected by Microsoft Defender Antivirus
Aliases: W32/IRCbot.gen (McAfee) Esbot (Symantec) BKDR_RBOT (Trend Micro) W32/Backdoor.EUR (F-secure) Esbot (Sophos) Win32.Esbot (CA)
Summary
Windows Defender Antivirus detects and removes this threat.
Worm:Win32/Esbot is a family of network worms that targets Microsoft Windows 2000 computers by exploiting the Windows Plug-and-Play buffer overflow vulnerability that is fixed with Microsoft Security Bulletin MS05-039. The worm can also infect computers running other Windows operating systems if it is delivered through e-mail, instant messaging, or other routes. The worm has a backdoor component that connects to an IRC server to receive commands from attackers.