Sinowal: the evolution of MBR rootkit continues

From Botnets.fr
Jump to: navigation, search

(Publication) Link to the old Wiki page : [1] / Google search: [2]

Sinowal: the evolution of MBR rootkit continues
Sinowal.knf-PrevX.png
Botnet
Malware Sinowal
Botnet/malware group
Exploit kits
Services
Feature
Distribution vector
Target
Origin
Campaign
Operation/Working group
Vulnerability
CCProtocol
Date 2011 /
Editor/Conference PrevX Labs
Link http://www.aall86.altervista.org/files/Sinowal_new_Analysis.pdf www.aall86.altervista.org (www.aall86.altervista.org Archive copy)
Author Andrea Allievi
Type

Abstract

In these last weeks of year here at PrevX labs, we found an interesting malware sample called Simowal.knf. This is the last evolution of famous MBR rootkit that begun its spreading in the year 2008. Rootkit in this incarnation has evolved a lot. We start speaking about its way of starting up...

Bibtex

 @misc{Allievi2011BFR799,
   editor = {PrevX Labs},
   author = {Andrea Allievi},
   title = {Sinowal: the evolution of MBR rootkit continues},
   date = {22},
   month = Feb,
   year = {2011},
   howpublished = {\url{http://www.aall86.altervista.org/files/Sinowal_new_Analysis.pdf www.aall86.altervista.org}},
 }