Difference between revisions of "Bredolab severely injured but not dead"

From Botnets.fr
Jump to navigation Jump to search
 
m (Text replacement - " blog.fireeye.com" to "")
 
(One intermediate revision by the same user not shown)
Line 5: Line 5:
|Licence=
|Licence=
|Video=
|Video=
|Link=http://blog.fireeye.com/research/2010/10/bredolab-severely-injured-but-not-dead.html blog.fireeye.com
|Link=http://blog.fireeye.com/research/2010/10/bredolab-severely-injured-but-not-dead.html
|Author=Atif Mushtaq,  
|Author=Atif Mushtaq,  
|NomRevue=FireEye Malware Intelligence Lab blog
|NomRevue=FireEye Malware Intelligence Lab blog

Latest revision as of 21:50, 5 August 2015

(Publication) Google search: [1]

Bredolab severely injured but not dead
Botnet Bredolab
Malware
Botnet/malware group
Exploit kits
Services
Feature
Distribution vector
Target
Origin
Campaign
Operation/Working group
Vulnerability
CCProtocol
Date 2010 / 26 octobre 2010
Editor/Conference FireEye
Link http://blog.fireeye.com/research/2010/10/bredolab-severely-injured-but-not-dead.html (Archive copy)
Author Atif Mushtaq
Type

Abstract

Today started with some good news. The mega botnet known as Bredolab has been taken down. Kudos to the Dutch police and involved ISPs.[...]But surprisingly, I was able to find one CnC server which is fully active at the moment. This CnC server is:

Bibtex

 @misc{Lua error: Cannot create process: proc_open(/dev/null): failed to open stream: Operation not permitted2010BFR861,
   editor = {FireEye},
   author = {Atif Mushtaq},
   title = {Bredolab severely injured but not dead},
   date = {Error: Invalid time.},
   month = Error: Invalid time.,
   year = {2010},
   howpublished = {\url{http://blog.fireeye.com/research/2010/10/bredolab-severely-injured-but-not-dead.html}},
 }