Sality

From Botnets.fr
Jump to navigation Jump to search

(Botnet) Link to the old Wiki page : [1] / Google search: [2]

Sality
Alias
Group Probing, Downloading
Parent
Sibling
Family
Relations Variants:

Sibling of: Pramro
Parent of:
Distribution of:
Campaigns:

Target
Origin
Distribution vector
UserAgent
CCProtocol P2P (Decentralized)
Activity /
Status
Language
Programming language
Operation/Working group

Introduction

Features

Associated images

Checksums / AV databases

Publications

 AuthorEditorYear
All-in-one malware: an overview of SalityNicolas FalliereSymantec2010
Analysis of a “/0” stealth scan from a botnetAlberto Dainotti
Alistair King
Kimberly Claffy
Ferdinando Papale
Antonio Pescapé
2012
Large-scale analysis of malware downloadersChristian Rossow
Christian Dietrich
Herbert Bosz
DIMVA2012
Maazben: best of both worldsRodel MendrezM86 Security labs2009
On botnets that use DNS for command and controlFelix C. Freiling
Christian J. Dietrich
Christian Rossow
Herbert Bos
Maarten van Steen
Norbert Pohlmann
Institute for Internet Security University of Applied Sciences Gelsenkirchen Gelsenkirchen, Germany2011
Pramro and Sality - two PEs in a podScott MolenkampMicrosoft2012
SIRv12Joe Faulhaber
David Felstead
Paul Henry
Jeff Jones
Jimmy Kuo
Marc Lauricella
Dave Probert
Tim Rains
Frank Simorjay
Holly Stewart
Matt Thomlinson
Scott Wu
Terry Zink
Dennis Batchelder
Shah Bawany
Joe Blackbird
Eve Blakemore
Sarmad Fayyaz
Nitin Kumar Goel
Ken Malcolmson
Nam Ng
Mark Oram
Daryl Pecelj
Microsoft2012
The Sality botnetNicolas FalliereSymantec2010
Win32/Sality newest component: a router’s primary DNS changer named Win32/RBruteBenjamin VanheuverzwijnESET2014
Zeroing in on malware propagation methodsJoe Faulhaber
David Felstead
Paul Henry
Jeff Jones
Ellen Cram Kowalczyk
Jimmy Kuo
John Lambert
Marc Lauricella
Aaron Margosis
Michelle Meyer
Anurag Pandit
Anthony Penta
Dave Probert
Tim Rains
Mark E. Russinovich
Weijuan Shi
Adam Shostack
Frank Simorjay
Hemanth Srinivasan
Holly Stewart
Matt Thomlinson
Jeff Williams
Scott Wu
Terry Zink
Microsoft2011