From Sakura to Reveton via Smoke Bot - or a botnet distribution of Reveton
Jump to navigation
Jump to search
(Publication) Google search: [1]
From Sakura to Reveton via Smoke Bot - or a botnet distribution of Reveton | |
---|---|
![]() | |
Botnet | Smoke Bot, Reveton |
Malware | |
Botnet/malware group | |
Exploit kits | Sakura |
Services | |
Feature | |
Distribution vector | |
Target | |
Origin | |
Campaign | |
Operation/Working group | |
Vulnerability | |
CCProtocol | |
Date | 2012 / 2012-09 |
Editor/Conference | |
Link | http://malware.dontneedcoffee.com/2012/09/from-sakura-to-reveton-via-smoke-bot-or.html (Archive copy) |
Author | Kafeine |
Type | Blogpost |
Abstract
“ In my study of Reveton's distribution, I encountered only Blackholes and another not named exploit kit ( which is now only spreading Urausy ). FBI warned about Reveton being spread via Citadel.
In this illustration it's not Citadel, it's a Smoke Bot which is pushing the Reveton.
Not so far..cause we often see Citadel pushing Smoke Bot...so it's just a matter of order/preference of the Botnet operator (note that the Smoke Bot we will study is pushing a LOT of stuff among which Andromeda, Citadel, and for Russia/Ukraine Carberp (sic) )
Bibtex
@misc{Lua error: Cannot create process: proc_open(/dev/null): failed to open stream: Operation not permitted2012BFR1187, editor = {}, author = {Kafeine}, title = {From Sakura to Reveton via Smoke Bot - or a botnet distribution of Reveton}, date = {01}, month = Sep, year = {2012}, howpublished = {\url{http://malware.dontneedcoffee.com/2012/09/from-sakura-to-reveton-via-smoke-bot-or.html}}, }