Kelihos Botnet: What Victims Can Expect
ID: 10c668fb-7055-5c9f-8c1f-79d04265543f
STIX ID: report--10c668fb-7055-5c9f-8c1f-79d04265543f
Feed Name: Zscaler Security Research Blog
Threat Score
Executive summary: This report analyzes a Kelihos botnet sample (rasta01.exe) that uses P2P-style SMTP for command-and-control, contacts many hundreds of remote IPs, drops packet-capture tools to harvest credentials from ports 21/25/110, and queries blacklist services (Spamhaus, Barracuda, Sophos) to classify infected hosts for use as spam relays or proxy C2 nodes — producing very noisy network traffic that can aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
