Whole Network Most Recent TOP10 Anti-Spam Tools Malware Spam Spam News

 

Mega-D Trojan Analysis

Filed in archive Malware by Sue Walsh on February 29, 2008

19082088.jpg
Secure works has released an excellent analysis of the Ozdock/Mega-D trojan, whuch is responsible for creating and adding to the Mega-D botnet. Here is an excerpt:
Some sample Ozdok filenames are icf.exe, icf32.exe, cacglivn.exe, guyymgvl.exe and mm27nov.exe. The (phony) embedded file description is "Microsoft Internet Countermeasures Framework". The older variants usually install themselves to %windows%\system32\svchost.exe:exe.exe or a similarly named alternate data stream (ADS). These streams are hidden from normal listing in Explorer or a command shell. Startup at boottime is facilitated by the addition of a system service labeled "ICF". Additionally, the system firewall settings are modified to add svchost.exe as an authorized application. mm27nov.exe does not appear to contain code to set up persistence across reboots, so it may simply be an update intended to be executed by an existing instance of Ozdok.
Check out more here-this is a must read!


Advertisement


Permalink: Mega-D Trojan Analysis
Tags: Anti  spam  Server  anti  spam  Anti  spam  for  exchange  Exchange  spam  Attachment  spam  Antiphishing  Spam  bl 

Trackback: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/115359



Advertisement


Advertisement


CW ToolbarInstall
RSSrss   | See all blog subscribe options
Googlegoogle   |   What is RSS?
Yahoo!yahoo
AddthisAddThis Feed Button
BloglinesBloglines
Newsletter
Advertisement - Book yours here.

Use our search feature to look for other interesting posts

Just this blog Whole network


Advertisement -
Book yours here..
TierOneAds


 
  • Would you like to have a new interactive marketing channel for your company? Learn more about Sponsored Blogs with Creative Weblogging. See how we helped companies like Weblin and cellity reach their goals.
  • Would you like to reach millions of blog readers every day? See you banner on hundreds of blogs with TierOneAds? Stay in control measuring conversion in real time. Register now.
  • Would you like to make more money blogging? Use TierOneAds a new platform that allows you as a blogger to set your prices per impression. Register now.
  • Do you have a blog with more than 50k page views from the US? Let us market your blog and earn great fix payments and bonuses.
  • Would you like to see your text link here? Let us know!
Advertisement
Book yours here.

TierOneAds


  • Other blogs in the same channel in the Creative Weblogging Network

Advertisement -
Book yours here..
TierOneAds






Advertisement - Book yours here..
 
Tagcloud: Announcements Anti-Spam Tools Archival Tools Events Fight! Malware Phishing Security measures Spam Spam News Sponsored Post Spyware