Win32/Zeus (alias Zbot)
Re: Trojan Zeus (alias ZBot)
What is "butthurt"?
- EP_X0FF
- Global Moderator
- Posts: 4872
- Joined: Sun Mar 07, 2010 5:35 am
- Location: Russian Federation
- Contact:
Re: Trojan Zeus (alias ZBot)
Ring0 - the source of inspiration
Re: Trojan Zeus (alias ZBot)
@EP_X0FF
This article was interested for you?
This article was interested for you?
- EP_X0FF
- Global Moderator
- Posts: 4872
- Joined: Sun Mar 07, 2010 5:35 am
- Location: Russian Federation
- Contact:
Re: Trojan Zeus (alias ZBot)
Not really, it was expected to something like this will appear. Kelihos sinkholing also criticized by homemade security "experts". It is always pretty cool criticise others work when yourself you doing nothing and hiding this under the "private converstations" 600+ length words BS blogposts.
Ring0 - the source of inspiration
PWS:Win32/Zbot.gen!AF: Another varient of Zbot
Hi Guys ,
I came across a zbot sample as flagged by virustotal. But this sample is not even citadel/ice 9 or old zeus .
any one help in identifying it correctly .
lots of encrypted UDP only trafffic .
https://www.virustotal.com/file/0a7adf0 ... /analysis/
Thanks
Leeno
I came across a zbot sample as flagged by virustotal. But this sample is not even citadel/ice 9 or old zeus .
any one help in identifying it correctly .
lots of encrypted UDP only trafffic .
https://www.virustotal.com/file/0a7adf0 ... /analysis/
Thanks
Leeno
You do not have the required permissions to view the files attached to this post.
Re: PWS:Win32/Zbot.gen!AF: Another varient of Zbot
Don't think that this is new, I saw it at least 4 month ago. Why you decided that this is different version of ZBot?
FYI: http://www.microsoft.com/security/porta ... bot.gen!AF
FYI: http://www.microsoft.com/security/porta ... bot.gen!AF
Encyclopedia entry
Updated: Sep 19, 2011 | Published: Jun 29, 2011
PWS:Win32/Zbot.gen!AF is a generic detection for variants of PWS:Win32/Zbot, a password stealing trojan.
- EP_X0FF
- Global Moderator
- Posts: 4872
- Joined: Sun Mar 07, 2010 5:35 am
- Location: Russian Federation
- Contact:
Re: PWS:Win32/Zbot.gen!AF: Another varient of Zbot
Take decrypted.
You do not have the required permissions to view the files attached to this post.
Ring0 - the source of inspiration
Re: Trojan Zeus (alias ZBot)
"One of the botnets was up and running again within 24 hours of the takedown on a brand new c&c server and continued with its business as usual."rkhunter wrote:Critical analysis of Microsoft Operation B71 (against ZBot/Zeus/SpyEye botnet)
http://blog.fox-it.com/2012/04/12/criti ... ation-b71/
Is this true?
- EP_X0FF
- Global Moderator
- Posts: 4872
- Joined: Sun Mar 07, 2010 5:35 am
- Location: Russian Federation
- Contact:
Re: Trojan Zeus (alias ZBot)
When you are running botnet and really thinking about it security you always have a plan B. Backup/alternative C&C servers, and maybe reserved bot version (Kelihos example). Only a complete takedown combined with law enforcement actions can guarantee that botnet is really dead at forever. So it is not a something unusual, or a fault from Microsoft. Authors of this article should do something instead of searching for mistakes in others actions.thisisu wrote:"One of the botnets was up and running again within 24 hours of the takedown on a brand new c&c server and continued with its business as usual."rkhunter wrote:Critical analysis of Microsoft Operation B71 (against ZBot/Zeus/SpyEye botnet)
http://blog.fox-it.com/2012/04/12/criti ... ation-b71/
Is this true?
Ring0 - the source of inspiration
Re: Trojan Zeus (alias ZBot)
https://www.virustotal.com/file/aa0e54c ... 335802170/
Detection Ratio: 14/43
MD5: 9fbd7c5d26fe75a6faffe29bee66ce40
Detection Ratio: 14/43
MD5: 9fbd7c5d26fe75a6faffe29bee66ce40
You do not have the required permissions to view the files attached to this post.