09.08.2015 Views

Rustock.C When a myth comes true

Rustock.C - When a myth comes true.pdf

Rustock.C - When a myth comes true.pdf

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The family's history<br />

• <strong>Rustock</strong> aka Spambot is able to send spam emails and<br />

always used top notch rootkit techniques to hide its tracks<br />

• First version (<strong>Rustock</strong>.A) appeared in Nov 2005, followed by<br />

<strong>Rustock</strong>.B in July 2006<br />

• Code maintained probably only by one Russian guy, who is<br />

known as "pe386" or "ntldr" in the underground<br />

• From a reverse engineers point of view, this malware family<br />

was always a challenging task and with every evolution<br />

step also the degree of analyzing difficulty increased<br />

3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!