Americas

  • United States

Asia

Oceania

roger_grimes
Columnist

Virus installs and uses Kaspersky AV engine to protect itself, plus more

Analysis
Oct 21, 20061 min
Data and Information SecuritySecurity

Interesting example of an advanced spambot. Joe Stewart at SecureWorks analyzed and reported on a spambot that uses Kaspersky antivirus to protect itself. Not only that, but it also: -Command and control bot with multiple server ports -Uses AES encryption to protect itself. -Adds random pixels to the end of the spam gif it uses to fool anti-spam software looking for static images. -Very modular -Uses a custom, b

Interesting example of an advanced spambot.

Joe Stewart at SecureWorks analyzed and reported on a spambot that uses Kaspersky antivirus to protect itself. Not only that, but it also:

-Command and control bot with multiple server ports

-Uses AES encryption to protect itself.

-Adds random pixels to the end of the spam gif it uses to fool anti-spam software looking for static images.

-Very modular

-Uses a custom, binary, P2P network.

Thanks to my friend Steve from SecurityAppraisers for the hint.

roger_grimes
Columnist

Roger A. Grimes is a contributing editor. Roger holds more than 40 computer certifications and has authored ten books on computer security. He has been fighting malware and malicious hackers since 1987, beginning with disassembling early DOS viruses. He specializes in protecting host computers from hackers and malware, and consults to companies from the Fortune 100 to small businesses. A frequent industry speaker and educator, Roger currently works for KnowBe4 as the Data-Driven Defense Evangelist and is the author of Cryptography Apocalypse.

More from this author