Darkshell DDOS Botnet Evolves With Variants

Darkshell is a distributed denial of service (DDoS) botnet targeting Chinese websites. It was found in 2011 and was www.mcafee.com/activate first analyzed by Arbor Networks. McAfee Labs recently analyzed a few new www.mcafee.com/activate download samples that turned www.mcafee/activate out to be variants of Darkshell, and we found extensive variations www.mcafee.com/activate product key in network traffic and control commands mcafee.com/activate product key. The Darkshell bot follows a fairly www.mcafee.com/activate product key standard installation process by copying itself into the System32 directory with a name that appears to be www.mcafee.com/activate legitimate, for example, C:\WINDOWS\system32\WinHe803.exe. It then sends the mcafee.com/activate product key system information of the infected machine to its control server in encrypted format. Once the control server receives the information, it responds www.mcafee.com/activate downlo...