logo

Necurs – hybrid spam botnet

ID: 6ada99fa-7f16-5493-a629-fe49572db4a4

STIX ID: report--6ada99fa-7f16-5493-a629-fe49572db4a4

Feed Name: CERT Polska

Threat Score
85/100

Date Published: 2016-09-02

Date Updated: 2026-04-19

Author: Adam Krasuski

...
...

This report presents a technical analysis of the Necurs botnet, a large-scale spam-distributing botnet that uses a hybrid centralized and P2P command-and-control architecture, a domain generation algorithm, encrypted resources and custom protocols to deliver payloads (notably the Locky ransomware). It documents Necurs's C2 and P2P message formats, resource structures, anti-analysis measures, the spam-sending DLL JSON format, and provides sample hashes and YARA rules to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.