The Artro botnet was created using a Trojan downloader that is detected by Kaspersky Lab as Trojan-Downloader.Win32.CodecPack. The Trojan is protected by a packer with heavily obfuscated code. Packers are used to prevent detection of a packed malicious program rather than to protect its code from analysis. The downloader checks for an Internet connection by sending DNS requests to popular websites, such as wordpress.com, walmart.com and photobucket.com. If the infected computer is online, the downloader collects information about it.”]
Source: https://securelist.com/the-advertising-botnet/35962/

