logo

Kelihos Botnet: What Victims Can Expect

ID: 10c668fb-7055-5c9f-8c1f-79d04265543f

STIX ID: report--10c668fb-7055-5c9f-8c1f-79d04265543f

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Executive summary: This report analyzes a Kelihos botnet sample (rasta01.exe) that uses P2P-style SMTP for command-and-control, contacts many hundreds of remote IPs, drops packet-capture tools to harvest credentials from ports 21/25/110, and queries blacklist services (Spamhaus, Barracuda, Sophos) to classify infected hosts for use as spam relays or proxy C2 nodes — producing very noisy network traffic that can aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.