Blog | G5 Cyber Security

Virut Analysis and Snort Rule

Virut (from virus + trojan) is a family of malware that has been around in since 2006. VirusBulletin says Virut was the 5th most prevalent in March 2009. Virus spreads from file to file by appending malicious code to clean files, making them some 20kb larger than before. Virut is highly polymorphic. Rules to detect detect detect Virut attempting to contact its command and control server will be released in the near future I will then update this blog post with the GIDs and SIDs.”]

Source: https://blog.talosintelligence.com/2009/05/virut-analysis-and-snort-rule.html

Exit mobile version