I just found a new backdoor program in the wild. It is a reverse backdoor that uses udp port 53 to communicate with the server side. It uses a couple of interesting techniques, for example, it injects itself in hidden IE instance.
I wrote a little paper about the analysis: http://www.klake.org/~jt/malware/spotcom/ Regards, -- Jarkko Turkulainen <[EMAIL PROTECTED]> _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
