evilMule in kernel mode – an analysis of the network functionality of Sirefef

2012-05-03

Chun Feng

Microsoft, Australia
Editor: Helen Martin

Abstract

Win32/Sirefef (a.k.a. ZeroAccess) is one of the most prevalent threats in the wild today. Its main component is a kernel-mode driver, which implements a kernel-mode P2P file distribution system to deploy new malware components and upgrade existing ones. Chun Feng describes the design and implementation of this P2P file distribution system.


The full article is available to registered users. Click here for free registration or, if you already are a registered user, login to access the full article.

Quick Links

Poll
Do current laws offer enough protection for ethical ('white-hat') hackers?
Yes, the current laws are fine
No, they prevent responsible disclosure of vulnerabilities
The current laws are too lax, we need to be stricter on hacking
I don't know
Leave a comment
View 4 comments

CISCO

VB2013
VB2013 VB2013 will take place 2 - 4 October 2013 at the Maritim hotel, Berlin, Germany.

Virus Bulletin currently has 227,267 registered users.