From Sakura to Reveton via Smoke Bot - or a botnet distribution of Reveton

From Botnets.fr
Jump to navigation Jump to search

(Publication) Google search: [1]

From Sakura to Reveton via Smoke Bot - or a botnet distribution of Reveton
Fstrvsb.png
Botnet Smoke Bot, Reveton
Malware
Botnet/malware group
Exploit kits Sakura
Services
Feature
Distribution vector
Target
Origin
Campaign
Operation/Working group
Vulnerability
CCProtocol
Date 2012 / 2012-09
Editor/Conference
Link http://malware.dontneedcoffee.com/2012/09/from-sakura-to-reveton-via-smoke-bot-or.html (Archive copy)
Author Kafeine
Type Blogpost

Abstract

In my study of Reveton's distribution, I encountered only Blackholes and another not named exploit kit ( which is now only spreading Urausy ). FBI warned about Reveton being spread via Citadel.

In this illustration it's not Citadel, it's a Smoke Bot which is pushing the Reveton.


Not so far..cause we often see Citadel pushing Smoke Bot...so it's just a matter of order/preference of the Botnet operator (note that the Smoke Bot we will study is pushing a LOT of stuff among which Andromeda, Citadel, and for Russia/Ukraine Carberp (sic) )

Bibtex

 @misc{Lua error: Cannot create process: proc_open(/dev/null): failed to open stream: Operation not permitted2012BFR1187,
   editor = {},
   author = {Kafeine},
   title = {From Sakura to Reveton via Smoke Bot - or a botnet distribution of Reveton},
   date = {01},
   month = Sep,
   year = {2012},
   howpublished = {\url{http://malware.dontneedcoffee.com/2012/09/from-sakura-to-reveton-via-smoke-bot-or.html}},
 }