A Day in the Life of the Rustock Botnet - Security - News & Reviews - eWeek.com

A Day in the Life of the Rustock Botnet

A Day in the Life of the Rustock Botnet
Written By
Brian Prince
Brian Prince
Jul 28, 2009
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More


A Day in the Life of the Rustock Botnet

A Day in the Life of the Rustock Botnet

by Brian Prince


Evolution of Rustock

2

This is a picture of the early evolution of the Rustock backdoor Trojan. Totmau is a Trojan Symantec found a few months before Rustock was discovered. Researchers there suspect the malware authors may be the same or connected, but that has not been established.


Rustock Code

3

This is the actual code Rustock uses to target victims.


Cracking Rustocks Code

4

Here is a flowchart of a Rustock sample using a method to make things difficult for analysts. The malware author twists the code on purpose in an attempt to obfuscate the real intention.


How It Happens

5

In this diagram, researchers outlined how the botnet works to infect users and spread spam.


Advertisement

A Side of Spam

6

Rustock is a sophisticated and prolific spamming machine. The individual spambots are among the fastest at sending spam that we have observed—we clocked one individual bot at 25,000 messages per hour from a standard desktop PC.


Communication Is Key

7

This image shows the flow of information a bot goes through when it queries the C&C server.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.