Sunday, January 3, 2010

Old Zeus DIY Still Evading Antivirus

The Zeus DIY malware construction kits can be purchased for anything between $4,000 to $0.00 - depending upon the age of the kit and the exploit packs shipped with it. One of the "most recent" Zeus kits circulating the bargain-basement hacking forums is version 1.2.4.2 - dated May 2009.

A colleague of mine over at Damballa, Christopher Elisan, posted a short educational walk-through of this Zeus version for the uninitiated - Zeus 4 U. It's worth noting just how easy it's become to generate new Zeus botnet agents - and what the configuration defaults are (e.g. the default banks the keylogger functions target).

Most surprisingly (and disappointingly) is how commercial antivirus detection of the malware created by this DIY kit is still languishing after seven months!

No comments:

Post a Comment