Get a Pentest and security assessment of your IT network.

News

Avzhan DDoS bot dropped by Chinese drive-by attack

The Avzhan DDoS bot has been known since 2010, but recently we saw it in wild again, being dropped by a Chinese drive-by attack. In this post, well take a deep dive into its functionality and compare the sample we captured with the one described in the past. After being deployed, the malware copies itself under a random name into a system folder, and then deletes the original sample. Its way to achieve persistence is by registering itself as a Windows Service. There are no UAC bypass capabilities inside the bot, so it can only rely on some external droppers.”]

Source: https://blog.malwarebytes.com/threat-analysis/2018/02/avzhan-ddos-bot-dropped-by-chinese-drive-by-attack/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2