<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Research</title>
	<atom:link href="http://re-malware.com/feed" rel="self" type="application/rss+xml" />
	<link>http://re-malware.com</link>
	<description>Without mysteries, it can not survive</description>
	<lastBuildDate>Sat, 03 Sep 2011 06:53:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Decrypt Zeus 2.3.2.0 Config File</title>
		<link>http://re-malware.com/archives/480</link>
		<comments>http://re-malware.com/archives/480#comments</comments>
		<pubDate>Sat, 03 Sep 2011 06:53:40 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[2.3.2.0]]></category>
		<category><![CDATA[AES]]></category>
		<category><![CDATA[zbot]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=480</guid>
		<description><![CDATA[Today, i came across a good blog from Trend. http://blog.trendmicro.com/zeus-gets-another-update/ &#160; But, the &#8220;F5&#8243; result is not that clear, so I decide to check it. I get the sample from https://zeustracker.abuse.ch/monitor.php?host=xoophafiel.ru Zbot version 2.3.2.0, thanks to its hardcoded parameter. &#160; After unpacked the binary, it turns out that not so much routine changed except the encryption algorithm [...]]]></description>
		<wfw:commentRss>http://re-malware.com/archives/480/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pushdo/Cutwail/Webwail Botnet Resurrects</title>
		<link>http://re-malware.com/archives/456</link>
		<comments>http://re-malware.com/archives/456#comments</comments>
		<pubDate>Thu, 18 Aug 2011 06:58:54 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[magadan]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[webwail]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=456</guid>
		<description><![CDATA[&#160; Since I wrote too many things about Pushdo/Cutwail/Webwail, this time i don&#8217;t want to actually write something. I believed some pics are better. &#160; &#160; -Kyle Yang]]></description>
		<wfw:commentRss>http://re-malware.com/archives/456/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The ‘New’ Storm</title>
		<link>http://re-malware.com/archives/414</link>
		<comments>http://re-malware.com/archives/414#comments</comments>
		<pubDate>Wed, 05 Jan 2011 05:52:27 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[strom3]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=414</guid>
		<description><![CDATA[Last week, ShadowServer have posted a great blog about this new p2p spam botnet. In this blog, I&#8217;ll mainly focus on its communication protocol and encryption algorithm of bot version 0.0.49. The following figure shows us its bootstrap before communication starts. 1. Update Peer List After the bootstrap, it will try to ‘talk’ to the [...]]]></description>
		<wfw:commentRss>http://re-malware.com/archives/414/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Farewell To Pushdo/Cutwail/Webwail Botnet – II (Denis and Joker)</title>
		<link>http://re-malware.com/archives/391</link>
		<comments>http://re-malware.com/archives/391#comments</comments>
		<pubDate>Tue, 05 Oct 2010 06:04:09 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[botnet tracker]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[webwail]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=391</guid>
		<description><![CDATA[In my last blog, Farewell To Pushdo/Cutwail/Webwail Botnet – I (Relationship with other malware gangs) I revealed the relationship between Pushdo gang and other malware gangs. Feel Interesting? Since I didn&#8217;t finish my demo in the VB100 2010 presentation. In this blog, I&#8217;ll try to point out some key features of Pushdo/Cutwail/Webwail Fuzzing Tracker. Tracker [...]]]></description>
		<wfw:commentRss>http://re-malware.com/archives/391/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Farewell To Pushdo/Cutwail/Webwail Botnet &#8211; I (Relationship with other malware gangs)</title>
		<link>http://re-malware.com/archives/383</link>
		<comments>http://re-malware.com/archives/383#comments</comments>
		<pubDate>Sat, 02 Oct 2010 09:37:35 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[antispyware]]></category>
		<category><![CDATA[asprox]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[CMultiLoader]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[fakeav]]></category>
		<category><![CDATA[goolbot]]></category>
		<category><![CDATA[gootkit 1.2]]></category>
		<category><![CDATA[GootkitTag]]></category>
		<category><![CDATA[magadan]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[restyle bot]]></category>
		<category><![CDATA[sasfis]]></category>
		<category><![CDATA[soldier]]></category>
		<category><![CDATA[TDSS]]></category>
		<category><![CDATA[webwail]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=383</guid>
		<description><![CDATA[In this blog, I&#8217;ll give a brief history of Pushdo/Cutwail/Webwail evolution and reveal its relationship with other malware gangs. Jan 2007 &#8211; 1st generation Pushdo, use http get command and has static parameters in the get command. Dec 2007 &#8211; 2nd generation Pushdo [Codename: Siberia2]. The author remove the static parameters from the get command. [...]]]></description>
		<wfw:commentRss>http://re-malware.com/archives/383/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pushdo/Cutwail Botnet is warming up to bounce back – V (Sasfis)</title>
		<link>http://re-malware.com/archives/377</link>
		<comments>http://re-malware.com/archives/377#comments</comments>
		<pubDate>Tue, 21 Sep 2010 07:10:52 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[sasfis]]></category>
		<category><![CDATA[sasfis tracker]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=377</guid>
		<description><![CDATA[Basically, we don&#8217;t work at weekend, but Pusho/Cutwail/Webwail gang, they did. After added 4 new cutwail servers. Today, they spread his old friend Sasfis again. Last time is 1st Sep 2010. Pushdo/Cutwail Botnet is warming up to bounce back – III (Sasfis, Asprox, Cutwail, FakeAV, Hiloti) Following is the screenshot from the cutwail spam template [...]]]></description>
		<wfw:commentRss>http://re-malware.com/archives/377/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Webwail Botnet and MSN</title>
		<link>http://re-malware.com/archives/358</link>
		<comments>http://re-malware.com/archives/358#comments</comments>
		<pubDate>Thu, 09 Sep 2010 06:19:24 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[webwail]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=358</guid>
		<description><![CDATA[Today, I made a BIG video of the process that Webwail register new MSN account for its spam purpose. Above is only one function of Webwail Botnet, its main purpose is send spam from those pre-registered MSN accounts. I&#8217;ll make another video on that. Webwail Reg MSN Routine: 1. Retrieve pre-defined MSN user info from [...]]]></description>
		<wfw:commentRss>http://re-malware.com/archives/358/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pushdo/Cutwail Botnet is warming up to bounce back – IV</title>
		<link>http://re-malware.com/archives/350</link>
		<comments>http://re-malware.com/archives/350#comments</comments>
		<pubDate>Thu, 02 Sep 2010 18:35:39 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[pushdo]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=350</guid>
		<description><![CDATA[Pushdo/Cutwail gang added another 4 new Cutwail C&#38;C servers today(till now). Now, they had 20 Cutwail C&#38;C servers alive. -Kyle Yang]]></description>
		<wfw:commentRss>http://re-malware.com/archives/350/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pushdo/Cutwail Botnet is warming up to bounce back – III (Sasfis, Asprox, Cutwail, FakeAV, Hiloti)</title>
		<link>http://re-malware.com/archives/327</link>
		<comments>http://re-malware.com/archives/327#comments</comments>
		<pubDate>Thu, 02 Sep 2010 05:19:16 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[asprox]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[fakeav]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[sasfis]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=327</guid>
		<description><![CDATA[In my previous 2 blogs( I and II), Pushdo/Cutwail gang already added 10 Cutwail servers. You might be interested in what spam they are sending now. Following(from my Pushdo/Cutwail Botnet Tracker)  is the spam template which cutwail bot retrieved from the new Cutwail C&#38;C servers. You may be too familiar with “DHL” spam. Of course, [...]]]></description>
		<wfw:commentRss>http://re-malware.com/archives/327/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pushdo/Cutwail Botnet is warming up to bounce back – II</title>
		<link>http://re-malware.com/archives/322</link>
		<comments>http://re-malware.com/archives/322#comments</comments>
		<pubDate>Tue, 31 Aug 2010 17:34:58 +0000</pubDate>
		<dc:creator>Kyle Yang</dc:creator>
				<category><![CDATA[Botnet Researching]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[pushdo]]></category>

		<guid isPermaLink="false">http://re-malware.com/?p=322</guid>
		<description><![CDATA[Just like I said in my previous blog, Pushdo/Cutwail gang will add more servers in this week.  Check the following info from my tracker. They added another 6 Cutwail C&#38;C servers. -Kyle Yang]]></description>
		<wfw:commentRss>http://re-malware.com/archives/322/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

