TDL4 – Top Bot - Securelist
TDL4 – Top Bot TDSS variants Yet another affiliate program The ‘indestructible’ botnet Encrypted network connections An antivirus of its own Botnet access to the Kad network Extended functionality The proxy server module 64-bit support Working with search engines Botnet command and control servers Command and control server statistics To be continued… TDSS variants The malware detected by Kaspersky Anti-Virus as TDSS is the most sophisticated threat today. TDSS uses a range of methods to evade signature, heuristic, and proactive detection, and uses encryption to facilitate communication between its bots and the botnet command and control center. TDSS also has a powerful rootkit component, which allows it to conceal the presence of any other types of malware in the system. Its creator calls this program TDL. Since it first appeared in 2008, malware writers have been perfecting their creation little by little. By 2010, the latest version wa...