A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #7033  by EP_X0FF
 Sat Jul 02, 2011 2:06 pm
rkhunter wrote:Matrosov wrote in Twitter that ESET update info about TDL botnet - http://www.eset.com/us/resources/white- ... of_TDL.pdf
=)
Nice read with good graphics, however it's seems to be slightly outdated (May 2011).
First post updated to include link to this article.
 #7041  by EP_X0FF
 Sat Jul 02, 2011 6:12 pm
I mean changes they did in rootkit component and dropper to neutralize KB2506014.
0000C428 result patch, new kdcom.dll export directory size lookup and miniport disk driver hook update for some TDL4 scanners bypass.
 #7043  by EP_X0FF
 Sat Jul 02, 2011 6:21 pm
The section 5.3 is the only description of what this KB did.
Current TDL4 successfully neutralized this patch by implementing stuff I described in previous post. This was made in the end of April.
There somewhere Prevx article with more detailed info, but I lost this link :)

Likely this ESET article was written in the middle of April, so it can't cover recent changes, that's why I called it "slightly outdated".
  • 1
  • 47
  • 48
  • 49
  • 50
  • 51
  • 60