IT NEWS     Sustainability    Get JOB ALERTS that match your skills
Technology news and Jobs arrow TAG
Kraken botnet evolving, says PC Tools PDF E-mail
User Rating: / 0
PoorBest 
by Stephen Withers   
Tuesday, 29 April 2008
A significant new variant of the Kraken malware has been identified by security researchers.

The new variant was detected by PC Tools' ThreatFire system, which looks for behaviour characteristic of malware rather than relying on signature-based detection. Researchers at the company claim signature-based tools have a poor detection rate for the new variant.

"PC Tools are [sic] revealing the details of the latest Kraken variant including the new list of domain names as well as the mathematical algorithm used," said Sergei Shevchenko, senior malware researcher at PC Tools.

"The source code of the Kraken domain name generation algorithm is disclosed in the interests of congregating all the knowledge about this bot so that other security specialists can benefit from it," he added.

According to PC Tools officials, the new Kraken variant uses a random word generator that can produce natural-looking though meaningless words for use in headers and URLs.

"The random word generator is possibly designed to evade spam filters and algorithms that have the ability to distinguish the 'randomness' of words by locating uncommon combinations of characters. If a rule or algorithm cannot be built to distinguish such a word then it cannot be detected or blocked," said Shevchenko.

CONTINUED



 
< Next story in category   Previous story in the category >
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff
Subscribe to our free e-newsletter
First name:
Last name:
Your email address:
Your role:
Your industry:
Australian state:
Country:
Enter the security code shown:
mandatory
Contact , Register , Advertise with iTWire , Links , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging , MyBlogLog page
Industry Releases , Submit your release now