Latest Comments
"Excellent info. If you use Gumtree Australia you will see many obvious scam posts in all ..."
by Marian Imrie | Dec 5, 2008 4:45 PM
 
"Very nice and useful information. UT4B4. Tape4backup.com"
by Lto-4 Tape | Dec 4, 2008 9:23 PM
 
"Interesting that you do not bother to list the one AV that has consistently passed the VB100. ..."
by Ben | Dec 4, 2008 6:00 PM
 
"I like this"
by nanwin | Dec 3, 2008 3:05 PM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM

Damballa responds to Kraken exaggeration claims

  • Email a Friend
  • Print Page
By Sue
Apr 14, 2008 4:33 PM
Tags: Damballa | responds | to | Kraken | exaggeration | claims
The accusations claim that Damballa misrepresented the high number of attacks from Kraken. A blog on F-Secure's website stated, “There are many detection names for ‘Kraken': Oderoor, Bobax, Agent, and many more. We believe that there is a single group of people behind Karken, updating their malware as time goes by. It's not new; it's just a new generation of something older.”

Damballa refuted these comments: “Damballa's initial disclosure says only that ‘Kraken was first observed in winter 2007, but investigation into its origins suggests the existence of early variants as far back as late 2006.' So is Kraken new? Damballa believes it is,” a statement released by the company on April 9 stated.

Paul Royal, principal researcher at Damballa, said the heart of the issue deals with the way information security professionals identify and categorize different entities based on their available sources and their organization's focus.

“I think a lot of people have looked at this issue from a purely malware analysis point of view,” Royal told SCMagazineUS.com on Thursday. “But people are calling it all the same thing if it has similar components or has a common author.”

The reason Damballa is calling Kraken new is because, although there are similarities between Kraken and Bobax and other threats, they use different C&C domains and communicate with the C&C in a fundamentally different way, he said.

“We're not just looking at the binaries,” said Royal, “but also at network activity. There are two distinct entities. If the server controls for Bobax were taken down, Kraken would continue and likewise.”

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers