Analyse von: Jesa Golez

 URL gesperrt am/um:Dienstag, 26. Februar 2013 13:25:00 GMT-8
 Bewertung:: Hoch
 Domäne:: admin0805.gnway.net
 Kategorie: Disease Vector
 Beschreibung:

BKDR_RARSTONE.A connects to this site to send and receive commands from a remote malicious user. The malware uses similar techniques as those of PlugX, including process injection and use of blob file.