Difference between revisions of "Reveton Autumn Collection += AU,CZ, IE, NO & 17 new design"

From Botnets.fr
Jump to navigation Jump to search
m (1 revision imported)
 
m (Text replacement - " malware.dontneedcoffee.com" to "")
 
Line 5: Line 5:
|Licence=
|Licence=
|Video=
|Video=
|Link=http://malware.dontneedcoffee.com/2012/10/reveton-autumn-collection-aucz-ie-no-14.html malware.dontneedcoffee.com
|Link=http://malware.dontneedcoffee.com/2012/10/reveton-autumn-collection-aucz-ie-no-14.html
|Author=Kafeine,  
|Author=Kafeine,  
|NomRevue=Malware don't need Coffee
|NomRevue=Malware don't need Coffee

Latest revision as of 19:00, 7 February 2015

(Publication) Google search: [1]

Reveton Autumn Collection += AU,CZ, IE, NO & 17 new design
Reveton2.png
Botnet Reveton
Malware
Botnet/malware group
Exploit kits Cool Exploit Kit
Services
Feature
Distribution vector
Target
Origin
Campaign
Operation/Working group
Vulnerability
CCProtocol
Date 2012 / 2012-10-12
Editor/Conference
Link http://malware.dontneedcoffee.com/2012/10/reveton-autumn-collection-aucz-ie-no-14.html (Archive copy)
Author Kafeine
Type

Abstract

After launching what I think is its own new "Cool" Exploit Kit initiating a new way in browser exploit pack to drop payload ("Duqu-like" font drop), the team ( ? behind Reveton) is using it to spread Reveton which dress from its C&C with a new "Autumn Collection" and is targeting at least 4 new countries : AU,CZ, IE & NO

Bibtex

 @misc{Lua error: Cannot create process: proc_open(/dev/null): failed to open stream: Operation not permitted2012BFR1229,
   editor = {},
   author = {Kafeine},
   title = {Reveton Autumn Collection += AU,CZ, IE, NO & 17 new design},
   date = {12},
   month = Oct,
   year = {2012},
   howpublished = {\url{http://malware.dontneedcoffee.com/2012/10/reveton-autumn-collection-aucz-ie-no-14.html}},
 }