Analyse von: Jesa Golez

 URL gesperrt am/um: martes, 26 de febrero de 2013 13:25:00 GMT-8
 Bewertung: : High
 Domain: : admin0805.gnway.net
 Category: Disease Vector
 DESCRIPTION:

BKDR_RARSTONE.A connects to this site to send and receive commands from a remote malicious user. The malware uses similar techniques as those of PlugX, including process injection and use of blob file.