Monday, March 18, 2013

Beta Bot - HTTP Botnet

Since this is my first post, allow me to introduce myself. Some of you might know me, and others may not. I'm a security software developer originally from Germany, and moved to the United States. That's really all you need to know about me :)


Anyway, on to the post.


Beta Bot is one of the higher tier bots you can purchase. It uses lower level hooks, unlike most bots. It has the capability to remove just about every other bot on the system, as well as cripple antiviruses, rendering your antivirus protection useless.

Complete list of antiviruses it can remove:



So with that being said, lets go on to capabilities. The bot has these functions:
  •  Complete persistence (File\Process\Registry)
  •  Usermode rootkit x64/x86
  •  System-Wide Injection (Injects into every process possible)
  • Advanced  'Botkiller' - Attempts to remove every other piece of malware on the system.
  •  Proactive Defense - Prevents other malware from being installed while Beta Bot is running.
  •  Distributed Denial of Service (UDP flood\Rapid Connect\Disconnect\HTTP GET\Slowloris)
  •  Form Grabber - Can be used to grab sensitive information. Supports Firefox\MSIE
 Complete list of antiviruses that the bot can remove:
  1. ArcaVir
  2. Avast!
  3. AVG
  4. Avira
  5. BullGuard
  6. Emsisoft Anti-Malware
  7. ESET NOD32 / Smart Security (All)
  8. F-PROT
  9. F-Secure IS
  10. GData IS
  11. Ikarus AV
  12. K7 AntiVirus
  13. Kaspersky AV/IS
  14. Lavasoft Adaware AV
  15. MalwareBytes Anti-Malware
  16. McAfee
  17. Microsoft Security Essentials
  18. Norman AntiVirus
  19. Norton AntiVirus (Vista+ only)
  20. Outpost Firewall Pro
  21. Panda AV/IS
  22. Panda Cloud AV (Free version)
  23. PC Tools AntiVirus
  24. Rising AV/IS
  25. Sophos Endpoint AntiVirus
  26. Total Defense
  27. Trend Micro
  28. Vipre
  29. Webroot SecureAnywhere AV
  30. Windows Defender
  31. ZoneAlarm IS




Extras:
 **I didn't take those screenshots.

No comments:

Post a Comment