06.02.2015 Views

Russian Business Network study - bizeul.org

Russian Business Network study - bizeul.org

Russian Business Network study - bizeul.org

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Version 1.0.1<br />

RBN <strong>study</strong> – before and after<br />

David Bizeul<br />

Torpig analysis 2007-07-23 Torpig analysis 2007-10-25<br />

It’s unpleasant to conclude that even 3 month after the reception of the file, this trojan has not been identified by most<br />

antivirus editors. Few (only 3) identify it properly as Torpig/Sinowal.<br />

Most major antivirus editors (Symantec, McAfee, Kaspersky or ClamAV) do not identify the threat. Those main editors<br />

may represent at least 50% marketshare. Most people think they are protected against malware because they have<br />

their miraculous antivirus but on this very issue, we can see people are still at risk and may encounter an identity theft at<br />

any time.<br />

The RBN Zoo<br />

It’s clear that RBN is hosting many, many, many kinds of malware. I did not give an example for each, but many well<br />

known malware have already been identified as being spread from RBN (Rustock, Haxdoor, Pinch…). Some antivirus<br />

editors provide on their website a description of sample malicious code collected. That can be used to identify whether<br />

RBN is implicated or no. An easy search on Exalead can also help to make up ones mind [ 11 ].<br />

11<br />

http://www.exalead.fr/search/resultsq=site%3a%28www.avira.com%29%20avira%20phishing%2081.95&nojs=1<br />

9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!