Last-minute paper reserve: The Waledac botnet: understanding it and breaking it

Pierre-Marc Bureau ESET
Joan Calvet Ecole Polytechnique de Montreal

The Waledac malware family clearly is Storm Worm 2.0: The code for both families is completely different but their functionalities and modus operandi are exactly the same. Waledac, just like Storm, uses a layered peer-to-peer network to communicate, propagates through malicious links, and is used to send huge amounts of spam. A bit like Web 2.0, Waledac introduces new vulnerabilities that were avoided by its predecessor.

In this presentation, we give an in-depth description of the Waledac malware family and its evolution. We explain the behaviour of its custom protection layer, its information-stealing capabilities and its business model. We also discuss the inner workings of its peer-to-peer network, how new peers connect to the network and how they send information back to the operators. Finally, we expose weaknesses that could be exploited to disrupt the botnet's activity and how Waledac's operators are working toward fixing them.

Quick Links



Poll

When do you install software updates?
As soon as they are released
As soon as I have some time
I take my time, but I always install them eventually
Only when I feel it is absolutely necessary
Never
Leave a comment
View 12 comments

Jobs Recruit Sidebar

Twitter Feed

virusbtn: RT @emailsecmatters: The typical spam message has sources as diverse as the spam lunch meat: http://ht.ly/2yucd
1 hour ago


virusbtn: Can anyone write a rap about our RAP tests (http://bit.ly/255ySQ) and submit it to the Symantec competition http://bit.ly/bOJg8r
5 hours ago


Virus Bulletin

In this month's magazine:
  • VB100 – Windows Vista Business Edition Service Pack 2
  • Apple pie order?
  • Anti-unpacker tricks – part eleven
  • Advanced exploit framework lab set-up
  • HTML structure-based proactive phishing detection
  • What’s the deal with sender authentication? Part 3
Virus Bulletin 08 2010
Subscribe now!
Virus Bulletin currently has 208,221 registered users.