Recommended for You:
Fix up your PC Fast

TuneUp Utilities 2012 takes out the trash: Get back long lost disk space and performance in a snap – Free Download!






You are not connected. Please login or register

View previous topic View next topic Go down  Message [Page 1 of 1]

1 New SPAM bot Troj_Proxy.aif on Sat Jun 13, 2009 2:29 am

DragonMaster Jay


Site Owner
Site Owner
It seems like a new spam bot is currently being developed. Few days ago it was posted a pretty good analysis of a relatively simple spam bot, which Trend Micro detects as TROJ_PROXY.AIF.
This spam bot is quite straightforward. On execution the trojan
(TROJ_PROXY.AIF) issues a DNS query to a single domain in order to
obtain an IP address in order to connects to a C&C (Command and Control ). The C&C traffic is in plain text and one can easily identify how the C&C works.


We say the TROJ_PROXY.AIF is simple because, unlike other spam bots like WALEDAC, the former does not have any C&C command encryption or a robust C&C (takedown the domain and they’re out of business).
One saving grace of this spam bot however, is its implementation of certain techniques to avoid spam filters.


http://blog.trendmicro.com/the-good-and-the-bad-of-being-a-new-spam-bot/


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

Ad Bot


View previous topic View next topic Back to top  Message [Page 1 of 1]

Permissions in this forum:
You cannot reply to topics in this forum