unixfreaxjp wrote:It has the botnet communication with HTTP & SSL, the SSL is for the handshake...avast! Blog / Mr. Ivan Jedek made a thorough payload binary analysis which is revealing the hidden C&C server information in the Cutwail payload binary.
Please check out his good reversing analysis in here: http://blog.avast.com/2013/06/25/15507/#more-15507
It worth to read, and I learned a lot by this post.