NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Trojan Horse Builds Peer-to-Peer Botnets

Via UDP port 4,000

By Marius Oiaga, Technology News Editor

20th of January 2007, 11:55 GMT

Adjust text size:


The Trojan.Peacomm (Trojan.Packed.8) is building a Peer-to-Peer botnet out of compromised machines. Security company Symantec has issued a public warning advising of the spamming
of the Trojan.Peacomm Trojan horse that is being spread via emails with the following subjects: "A killer at 11, he's free at 21 and kill again!," "U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel," "British Muslims Genocide," "Naked teens attack home director," "230 dead as storm batters Europe" and "Re: Your text."

The email additionally contains an attachment that is designed to appear as a video clip. "The executable drops a system driver (wincom32.sys, also detected as Trojan.Peacomm), which injects some payload and hidden threads directly into the services.exe process, using a sophisticated technique similar to Rustock (see Mimi Hoang's blog and Elia Florio's blog). However, in spite of its name, wincom32.sys driver is not a "real" rootkit as it does not hide its presence or its registry keys in the system," explained Amado Hidalgo, Sr. Security Response Manager Symantec.

Hidalgo explained that Trojan.Peacomm, once on a compromised system, debuts Peer-to-Peer communications on UDP port 4,000. Once the connection is established, the Trojan horse will download and execute additional malware.

"When it manages to connect to any of these initial IP addresses, it receives a list of additional IP addresses of infected machines and adds them to its list of available peers, building up a distributed network to aid in the download of more malware. The Trojan also keeps a "blacklist" of unsuitable peers. Part of this encrypted P2P configuration is stored in a file peers.ini stored in the %System% folder," added Hidalgo.
Read by 8,407 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.0/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Norton Will Be Ready in Time for Windows Vista

Will Microsoft Permit Symantec to Take Over Vista's UAC?

Download the Windows Vista DVD Covers

Symantec Wants Control Over Vista's UAC

Microsoft Continues to Forecast Vista Revenue for 2007

Windows Is the Number One Source of Computer Problems

Neutral and Positive Feedback for Vista APIs

Windows Vista ReadyBoost Test

Highly Critical PDF Vulnerability

Windows Vista Goes on the Coach Tour

Windows Vista Is Plagued with Vulnerabilities

Windows Vista Maximum Supported RAM

The 12 to Guard Vista

Windows Home Server to Cure Digital Dysfunctions

MMS Exploit Available for Windows Mobile

Windows Vista Is Unaffected by the VML Vulnerability

Mozilla to Update Firefox 2.0 for Vista

Hackers Update Windows Vista Activation Crack

Windows Home Server to Integrate Seamlessly with Windows Vista

Microsoft Confirms NSA Feedback with Vista

Windows Mobile and SD Cards Functionality Issues

Chinese Activation Crack for Windows Vista Available

Security Insight on Windows Home Server

Vista BitLocker and EFS Enhancements

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM