Jump to content
Tuts 4 You

Recommended Posts

Posted

Called TDL, TDSS, Alureon or Olmarik. First widely spreaded x64 rootkit.

Analysis:
/>http://www.prevx.com/blog/154/TDL-rootkit-x-goes-in-the-wild.html
/>http://www.prevx.com/blog/155/x-TDL-rootkit--follow-up.html
/>http://www.symantec.com/connect/de/blogs/tidserv-64-bit-goes-hiding
/>http://blog.raidrush.ws/2010/09/11/malware-analyse-tdl-rootkit-64-bit-infektion/ (german, but with TDL dropper source code)

download: http://www.xup.in/dl,15799673/TDL_x64.rar/

password: infected

Posted

Hi,

Dedicated thread about TDL3, first public dropper of the x64 variant could be found here :
/>http://www.kernelmode.info/forum/viewtopic.php?f=16&t=19

  • 2 weeks later...
Posted

never cease to amaze me K11

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...