« RansomWare on the loose.. | Main | BotnetWeb - Part II »

2009.04.22

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d835018afd53ef01156f4b5c64970c

Listed below are links to weblogs that reference Hexzone, RansomWare and, Finjan:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Thanks Finjan for this clarification,

Yes definitely, it is what was described in earlier post by you guys and I illustrated the same fact as:
From my post..

"Although Finjan did not mention the name of the botnet in their blog post, VirusTotal scan results (for one of the *secondary* downloads) shown in their article identified it as the *dropper* for a known Trojan called Hexzone."
Here, I am saying Hexzone as the secondary download and mega botnet as the dropper.

Atif Mushtaq

Dear FireEye,

Finjan's blog post shows VirusTotal report and indicates on Hexzone as an executable the bot was instructed to download from the command center.

Hexzone is not the bot itself but one out of many executables that the bot downloaded and executed on the infected PCs.

Taken from the blog post:
"This command instructs the bot on the infected computers to download and execute a Trojan horse. As indicates on the VirusTotal report below, only 4 out of 39 Anti-Virus products detected this Trojan."

if this guy is in the UK, why not simply shut him down?

The comments to this entry are closed.

Enter your email address:

Delivered by FeedBurner

Bookmark and Share

Twitter Updates

    follow me on Twitter

    In The News