Skip to content

Malware

ZeroAccess

aka Max++ · Sirefef · Smiscer · ZAccess

ZeroAccess is a modular botnet that was primarily active around 2012.

ZeroAccess, also known as Max++, Sirefef, Smiscer, ZAccess, is a Windows malware family.

Background

ZeroAccess is a modular botnet whose main period of activity was around 2012. Researchers saw it push fake antivirus software onto victims, carry out click fraud, and install bitcoin miners. It combines peer-to-peer communication with a centralized C&C, and it spoofs the HTTP Host header using bogus DGA-generated domains to mislead analysts. Although there is no indication the malware ever deliberately reached out to those DGA domains, malfunctioning middleboxes nonetheless directed some requests to them.


Source: Malpedia (Fraunhofer FKIE).