Free Newsletters

   All InfoWorld Newsletters
Security Adviser | Roger A. Grimes » Virus installs and uses Kaspersky AV engine to protect itself, plus more

October 21, 2006 | Comments: (0)

Virus installs and uses Kaspersky AV engine to protect itself, plus more

Interesting example of an advanced spambot.

Joe Stewart at SecureWorks analyzed and reported on a spambot that uses Kaspersky antivirus to protect itself. Not only that, but it also:

-Command and control bot with multiple server ports
-Uses AES encryption to protect itself.
-Adds random pixels to the end of the spam gif it uses to fool anti-spam software looking for static images.
-Very modular
-Uses a custom, binary, P2P network.


Thanks to my friend Steve from SecurityAppraisers for the hint.

Posted by Roger Grimes on October 21, 2006 12:27 PM


RATE THIS ARTICLE:





 

  •  
  • COMMENTS





Technology White Papers

 

InfoWorld Technology Marketplace

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
» BUY A LINK NOW

Sponsored Technology Links