Virut

First seen
2006-01-01 00:00:00
Malware type
botnet, virus
Family
Malware family
Last IoC activity
2026-07-22 01:18:59
Profile updated
2026-07-07 14:51:48

Context

Virut is a polmorphic malware known for its ability to infect executable files and spread through removable drives and network shares. It is part of a botnet used primarily for sending spam and distributing other malware. Virut is notorious for its persistence and adaptability, making it difficult to remove.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Virut_Auto (yara-rule)

Related threat objects

  • Virut (infrastructure)

Reports & references

  • Mandiant — Pe File Infecting Malware Ot (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Virut (report)
  • theregister.co.uk — Taiwanese Police Malware (report)
  • krebsonsecurity.com — Polish Takedown Targets Virut Botnet (report)
  • secureworks.com — Virut Encryption Analysis (report)
  • blog.malwarebytes.com — Blast From The Past Stowaway Virut Delivered With Chinese Ddos Bot (report)
  • Kaspersky — 36305 (report)
  • chrisdietri.ch — Virut Resurrects (report)
  • spamhaus.org — Cooperative Efforts To Shut Down Virut Botnet (report)
  • virusbulletin.com — Injection Way Life (report)

External references