logo

white-papers-avar-2012-festi-botnet-analysis-investigation.pdf

ID: 0b4cde6f-61bd-4c8b-af09-4fd996043bed

STIX ID: report--0b4cde6f-61bd-4c8b-af09-4fd996043bed

Threat Score

80/100

Uploaded: 2026-08-05

Published Date: 2026-08-05

Last Modified Date: 2026-08-05

Created by: gogogo

TLP:GREEN
...
...
**Executive summary:** This technical analysis of the Win32/Festi botnet (Matrosov & Rodionov) details a kernel-mode rootkit-based botnet used extensively for spam distribution and targeted DDoS attacks, describing its dropper/driver/plugin architecture, C&C protocol and domain/IP migrations, and advanced evasion techniques (kernel-mode TCP/UDP use to bypass HIPS/firewalls, VM detection, anti-debugging, in-memory plugins).