Sunday, November 5

Virus using Antivirus engine

Virus installs and uses Kaspersky AV engine to protect itself:

Interesting example of an advanced spambot.

Joe Stewart at SecureWorks analyzed and reported on a spambot that uses Kaspersky antivirus to protect itself. Not only that, but it also:

-Command and control bot with multiple server ports
-Uses AES encryption to protect itself.
-Adds random pixels to the end of the spam gif it uses to fool anti-spam software looking for static images.
-Very modular
-Uses a custom, binary, P2P network.

by Roger Grimes Infoworld

