Featured Research Updates — 18 June 2010
So you got: Clampi/Ilomo

So you got one of the most interesting pieces of Malware I have every had the displeasure of doing IR on…

Multi-Stage, evolving, silent…

It seems to always come from drive-by attacks and silently waits for the C&C to provide instructions…

I drops onto the system and creates a number of registry keys with difficult to anticipate keys, and files with semi random names. That can make it hard to find, but the one key you can count on appearing is,

HKCUSoftwareMicrosoftInternet ExplorerSettingsGateslist

The most important thing you can do to prevent the spread of Clampi/Ilomo once it is on your network is to do no work with Domain Administrator privileges. One of the most dangerous aspects of Clampi/Ilomo is its ability to log user credentials and use them to spread across your network using legitimate tools like PSEXEC.

@echo off && reg query HKCUSoftwareMicrosoftInternet ExplorerSettingsGateslist /s || echo Does not Exist!!!!

Ilomo Botnet analyzation by TrendMicro

Related Articles

Share

About Author

Rev. Richard E. Baker

Do A Little Dance...

(0) Readers Comments

Leave a Reply