English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

A few words about the HLux botnet

Dmitry Bestuzhev
Kaspersky Lab Expert
Posted January 04, 23:07  GMT
Tags: Microsoft Windows, Botnets, Spammer techniques, Campaigns, Email
0.4
 

Today my colleague Jorge Mieres found some interesting information related to the new HLux botnet.

This new worm is propagating via e-mail with a backboned administration through a crimeware pack called BOMBA. The scam messages come with a message to a fake eCard requiring installing Flash Player (an old scammers trick).

 
After the infection, the newly installed malware downloads a malicious update which is detected by Kaspersky as Email-Worm.Win32.Hlux.c and establishes a connection with BOMBA’s server reporting statistics about the infection.

 
Our statistics for Jan 5 show countries with the highest infection attempts are the U.S., Germany and the U.K.
 

We’ll keep researching this issue and will keep you updated.


4 comments

Newest first
Table view
 

zero

2011 Jan 16, 01:19
0
 

(:

look at them...
http://img18.imageshack.us/img18/8280/1612011.jpg
fake AV and ransomware...

Reply    

Jinesh

2011 Jan 12, 13:46
0
 

HTTP botnet

any new idea about HTTP botnet?

Reply    

Dmitry Bestuzhev

2011 Jan 07, 16:55
-1
 

Re: Waledac 2.0?

Yes

Reply    

koriaky

2011 Jan 05, 20:15
0
 

Waledac 2.0?

Hi, I was wondering if this botnet is similar to the one posted at: http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230

Please advise.
~K

Reply    
If you would like to comment on this article you must first
login


Bookmark and Share
Share

Analysis

Blog

Alerts