Peaches Posted July 23, 2009 Report Share Posted July 23, 2009 22New KOOBFACE Upgrade Makes It Takedown-Proofby Jonell Baltazar (Advanced Threats Researcher) Early this week, the KOOBFACE Command and Control (C&C) servers issued a new command to its downloader component. This new command identifies a list of IP addresses to be used by the downloader component as Web or relay proxies to retrieve subsequent commands and components. In the old KOOBFACE architecture (see Figure 1), the downloader directly connects to an available C&C to receive commands. However, the new command seen early this week actually changes the KOOBFACE botnet architecture to something more like the diagram in Figure 2.Details & screenshots - http://blog.trendmicro.com Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.