logo

Cooperative Efforts To Shut Down Virut Botnet

ID: 07c90d11-6ecc-501a-9dd8-a2f0e40df6ec

STIX ID: report--07c90d11-6ecc-501a-9dd8-a2f0e40df6ec

Feed Name: The Spamhaus Project

Threat Score
75/100

Date Published: 2013-01-19

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

Spamhaus describes the takedown efforts against the Virut botnet, a file‑infector/worm that spread via removable media and network shares and is estimated to have compromised over 300,000 machines. The report explains how operators used dozens of C2 domains primarily in the .pl, .ru and .at ccTLDs, that Virut was dropping ZeuS and Kehlios via a pay‑per‑install model, and documents cooperative sinkholing and domain suspensions in .pl and .ru while .at remained a remaining stronghold.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.