A case study of the rustock rootkit and spam bot

Ken Chiang, Levi Lloyd · Conference on Workshop on Hot Topics in Understanding Botnets · 2007

In this paper we present a case study of the steps leading up to the extraction of the spam bot payload found within a backdoor rootkit known as Backdoor.Rustock.B or Spam-Mailbot.c. Following the extraction of the spam module we focus our analysis on the steps necessary to decrypt the communications between the command and control server and infected hosts. Part of the discussion involves a method to extract the encryption key from within the malware binary and use that to decrypt the communications. The result is a better understanding of an advanced botnet communications scheme.

Read the paper · More papers on PaperTik