SYSREVEAL

GoolBot – if loving you is wrong, I dont want to be right

by on Feb.04, 2010, under Malware Research

Goolbot, another Bredolab like malware. The name came from its binary which has the strings “Google Bot”,  filled the “User-Agent” in the initial communication request. Surprisingly, it’s quite straight-forward, no fancy encryption, just plain text http.  That’s why i love it.

Server response on 30th Jan.

Server response on 3rd Feb.

You may find that, the list changed. Yes, that is the most important characteristic of GoolBot. It will download massive malware onto your computer, turn it to multi-function bot. Usually, it will download FakeAV downloader, Pushdo/Cutwail, Zbot, etc.  For the simple solution, you could just block the domain name – klitar.cn.


Comments are closed.

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!

Blogroll

A few highly recommended websites...