A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #8782  by rkhunter
 Tue Sep 27, 2011 5:53 pm
Building on the recent successes of the Rustock and Waledac botnet takedowns, I’m pleased to announce that Microsoft has taken down the Kelihos botnet in an operation codenamed “Operation b79” using similar legal and technical measures that resulted in our previous successful botnet takedowns.
DCU: http://blogs.technet.com/b/microsoft_bl ... -case.aspx

Documents: http://www.noticeofpleadings.com/

Technet post: http://blogs.technet.com/b/mmpc/archive ... lease.aspx
 #11253  by EP_X0FF
 Wed Jan 25, 2012 4:47 am
There in original post nowhere isn't stated any affiliation with Agnitum in case of Waledac/Hlux/Kelihos.
on a yellow pages aggregator "krebsonsecurity" stated that guy worked in agnitum while coding waledac(kelihos)
This is question of professionalism of the author, which is obviously lacks. It misses whole point and only found Agnitum as target for his yet another yellow blogpost about nothing. Perfect continuation of failures such as TDL4 car googling, WinAD "investigation" etc.

If tomorrow someone find the customized Zbot sources with references to his domain then, following this "expert" logic, he will be affiliated with Zeus botnet. What a pity.
 #11254  by rkhunter
 Wed Jan 25, 2012 5:23 am
Seems krebsonsecurity author was first who guessed to look on linkedin profile of this guy. But I agree that arcicles from blog increasingly began to resemble of yellow pages.
 #12440  by rkhunter
 Sat Mar 31, 2012 3:59 pm
Flamef wrote:
rkhunter wrote:New Kelihos/Hlux version found - Kelihos.C - Backdoor:Win32/Kelihos.F and botnet too http://www.darkreading.com/advanced-thr ... riant.html
New Kelihos/Hlux botnet bites the dust :D http://www.securelist.com/en/blog/20819 ... hos_Botnet

FAQ:Disabling the new Hlux/Kelihos http://www.securelist.com/en/blog/20819 ... hos_Botnet
You talking about .B variant. Kaspersky neutralized .B variant. .C was observed two days ago and new botnet works fine.