Virut
- First seen
- 2006-01-01 00:00:00
- Malware type
- botnet, virus
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:18:59
- Profile updated
- 2026-07-07 14:51:48
Context
Virut is a polmorphic malware known for its ability to infect executable files and spread through removable drives and network shares. It is part of a botnet used primarily for sending spam and distributing other malware. Virut is notorious for its persistence and adaptability, making it difficult to remove.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Virut_Auto (yara-rule)
Related threat objects
- Virut (infrastructure)
Reports & references
- Mandiant — Pe File Infecting Malware Ot (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Virut (report)
- theregister.co.uk — Taiwanese Police Malware (report)
- krebsonsecurity.com — Polish Takedown Targets Virut Botnet (report)
- secureworks.com — Virut Encryption Analysis (report)
- blog.malwarebytes.com — Blast From The Past Stowaway Virut Delivered With Chinese Ddos Bot (report)
- Kaspersky — 36305 (report)
- chrisdietri.ch — Virut Resurrects (report)
- spamhaus.org — Cooperative Efforts To Shut Down Virut Botnet (report)
- virusbulletin.com — Injection Way Life (report)