A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #26875  by faribadanesh
 Sat Oct 03, 2015 12:15 pm
Hi all
i am trying to run a TDL4 version and collect the network traces, i need the traces related to kad network as cmd.
i need a new version, dose any one has the latest version of tdl4?
dose any on has some network traces collected before?
thank you
 #26887  by EP_X0FF
 Tue Oct 06, 2015 10:50 am
Hello,

how many TDL4, exactly TDL4 droppers (not SST/MaxSS, not Pihar), did you saw since 2010? :)
 #26920  by faribadanesh
 Sun Oct 11, 2015 11:12 am
thank you EP_X0FF
do you know any other parasite p2p botnet? (parasite = botnets which use an existing p2p network as their c&c channel)