Vobfus
Aliases: Beebone
- First seen
- 2009-06-01 00:00:00
- Malware type
- worm, downloader
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:16:26
- Profile updated
- 2026-07-07 15:25:40
Context
Malware of this family searches for computers on a network and creates copies of itself in folders with open access. For the program to be activated, the user must first run it on the computer. The code of this malware is written in the Visual Basic programming language and uses obfuscation, which is a distinguishing feature of this family. Code obfuscation complicates attempts by anti-virus software to analyze suspected malware.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Vobfus_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Vobfus (report)
- contagiodump.blogspot.com — Nov 2012 Worm Vobfus Samples (report)
- Trend Micro — Beebone Botnet Takedown Trend Micro Solutions (report)
- Trend Micro — Whats The Fuss With Worm Vobfus (report)