Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.

Windows 7: New ZeuS-based modular rootkit offered to cybercriminals

16 Mar 2013   #1
A Guy

Microsoft Community Contributor Award Recipient

Windows 7 Home Premium x64 SP1
New ZeuS-based modular rootkit offered to cybercriminals

Given the popularity of the Zeus crimeware, and the fact that its source code has been ultimately offered for sale at bargain basement prices, it's no wonder that every now and then malware based on it gets offered on underground forums.

The latest of these is a bot with rootkit functionality unearthed by Dancho Danchev, and it apparently:

encrypts the communication between the C&C servers and the bots so that the botnet's owner is the only one that can control it

uses a Domain Generation Algorithm so that the bot will know which C&C servers to contact if the current ones get blocked or shut down

can drop a third-party piece of malicious code onto the affected computer

allows the botmaster to set random intervals for the bot to communicate with the C&C servers

allows the botmaster to "hide files on the disk, the branches in the registry, inject .dll in a separate process

and in all, provides a gateway through which the user applications can get a list of processes currently loaded kernel modules, terminate any process, to hide the list of dll modules loaded process."

A Guy

My System SpecsSystem Spec


 New ZeuS-based modular rootkit offered to cybercriminals

Thread Tools

Similar help and support threads
Thread Forum
Modular PSU - really neat
I think I made a pun. :p When I upgraded my on-chip video to video card I went ahead and upgraded the PSU. After reviewing PSUs I decided on the Seasonic S12II 520 Bronze for $65 plus $9.65 shipping. As I looked further I saw the modular version of said PSU (M12II) for $80 (free shipping) which...
Hardware & Devices
Require (Rootkit.TDSS.TDL4) Rootkit Removal & Cleanup walkthrough
I would really appreciate some help from someone with experience with this matter. Introduction: Origin: False sense of security by AVG (updated), Windows kept updated, Browser settings, firewall, and self system maintainence. Presentation: Installed a 2nd HDD (Exclusively for daily...
System Security
ZeuS Development Might Continue as Source Code Offered for Sale
ZeuS Development Might Continue as Source Code Offered for Sale - Softpedia
Security News
Xi3 Modular Computer
Neat :) Xi3 Modular Computer | iTech News Net - Gadget News and Reviews A Guy
Chillout Room
MS. - Scareware Indictments Put Cybercriminals on Notice
Source Scareware Indictments Put Cybercriminals on Notice - Microsoft On The Issues
Zeus-Themed Spam Used to Push Zeus.
Source - Zeus-Themed Spam Used to Push Zeus - Legit articles hijacked to spread malware - Softpedia
Security News

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 23:18.

Twitter Facebook Google+

Windows 7 Forums

Seven Forums Android App Seven Forums IOS App