I just found a new backdoor program in the wild. It is a reverse backdoor
that uses udp port 53 to communicate with the server side. It uses a
couple of interesting techniques, for example, it injects itself in hidden
IE instance.

I wrote a little paper about the analysis:

http://www.klake.org/~jt/malware/spotcom/



Regards,

--
Jarkko Turkulainen <[EMAIL PROTECTED]>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

Reply via email to