Alureon trojan uses steganography to receive commands
Researchers at Microsoft have discovered a new variant of the 'Alureon' trojan that uses steganography to make itself invincible against the takedown of botherders' domains.
Steganography, sometimes referred to as 'hiding in plain sight', is the art and science of writing messages in such a way that no one but the intended recipient would even suspect that a message is present. Images are often used for this purpose: the sender uses an existing image and modifies the least significant bit(s) of the colour components of each pixel to contain the message. The difference between the old and the new image will be barely noticeable, but the intended recipient can easily extract the message from it.
Alureon (which also goes by the name of TDSS or TDL) is an oft-researched malware family that uses a number of advanced techniques to avoid detection and increase redundancy. Steganography is the latest such technique: the malware is capable of downloading innocent-looking images from free hosting sites. These images contain an updated configuration file and thus provide an extra layer of redundancy against the domains used by the malware becoming unavailable.
With malware researchers and law enforcement agencies becoming increasingly successful in taking down malicious domains and command and control centres used by botherders, the latter are constantly looking for new ways to control their bots. The use of steganography, as well as for instance the use of DNS TXT records by the Morto worm, show that malware researchers should keep their eyes wide open and may find control commands to be hidden in places where they might least expect them.
source : http://www.virusbtn.com/index
Posted in
virus
Related posts:
If you enjoyed this article, subscribe to receive more great content just like it.
Popular Posts
-
DOWNLOAD NOW Full DVD Ripper Pro rips DVD movies to AVI, MPEG, WMV, DivX, MP4, H.264/MPEG-4 AVC, RM, MOV, XviD, 3GP videos, as well ...
-
Last week Microsoft introduced Windows 8 to the public via a developer preview build ( learn more about the Windows 8 developer...
-
DOWNLOAD NOW Sim card information Backup Machine recovers accidently deleted inbox, outbox, draft messages, address book etc. Datopal SIM...
-
Researchers at Microsoft have discovered a new variant of the 'Alureon' trojan that uses steganography to make itself invincible a...
-
DOWNLOAD NOW Adobe® Reader® software is the free global standard for reliably viewing, printing, and commenting on PDF documents. It...
-
Version 12 (September 15, 2011) of Sony’s new online services terms of service agreement (PDF) states, on page 18: Any dispute resolutio...
-
What do you do if your LCD tv is broken? buy new products, bring to place of repair, or fix it yourself ? in this article I will share abou...
-
to get a lot of visitors on our website, of course, much work to be done. very unlikely if we simply write just to write it but there is no ...
-
Many people have been using their personal computers to watch news, TV programs and movies. However, it's now very easy to set up your c...
-
The success of Twitter‘s Promoted Products will propel the company into $400 million in revenue in 2013 compared to $45 million last year...
Search
0 comments for this post
Leave a reply