white-papers-avar-2012-festi-botnet-analysis-investigation.pdf
ID: 0b4cde6f-61bd-4c8b-af09-4fd996043bed
STIX ID: report--0b4cde6f-61bd-4c8b-af09-4fd996043bed
Threat Score
80/100
Uploaded: 2026-08-05
Published Date: 2026-08-05
Last Modified Date: 2026-08-05
Created by: gogogo
TLP:GREEN
...
...
**Executive summary:** This technical analysis of the Win32/Festi botnet (Matrosov & Rodionov) details a kernel-mode rootkit-based botnet used extensively for spam distribution and targeted DDoS attacks, describing its dropper/driver/plugin architecture, C&C protocol and domain/IP migrations, and advanced evasion techniques (kernel-mode TCP/UDP use to bypass HIPS/firewalls, VM detection, anti-debugging, in-memory plugins).
