Researchers documented fresh ZeroAccess (also known as Sirefef, 0Access, ZAccess, Max++, and Smiscer) samples that remained in contact with active command-and-control infrastructure and used stealth techniques to persist on infected Windows systems. The malware was distributed through lure filenames posing as free videos, pornography, Flash Player updates, and generic readme executables, then injected a hidden library into Explorer.exe and stored components in concealed paths such as RECYCLER and $Recycle.Bin. Analysts reported that common cleanup tools struggled to expose the infection after compromise, requiring memory extraction of the hidden DLL to recover artifacts tied to filesystem manipulation, cryptographic functions, and peer-to-peer components such as p2p.32.dll.
Reverse-engineering references describe ZeroAccess as an advanced rootkit platform built around a user-mode dropper, a kernel-mode stealth driver, and process injection, with operators using it to silently install additional malware including FakeAV and potentially credential- or finance-theft payloads. Network captures from one infected host showed communications with numerous external IP addresses, including 81.17.26.187 and 67.81.86.2, consistent with the botnet's peer-to-peer activity, while antivirus detections identified the samples under names such as ZAccess, Sirefef, Kryptik, and generic trojan labels. Supporting analysis also linked parts of the malware's hosting and origin infrastructure to Ecatel and alleged ties to the Russian Business Network (RBN).

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
VirusTotal analysis dated 2012-12-26 showed at least two of the December 2012 ZeroAccess samples were each detected by 14 antivirus engines, including one sample with MD5 251a2c7eff890c58a9d9eda5b1391082 and another with MD5 a2611095f689fadffd3068e0d4e3e7ed. The detections labeled the files as ZAccess, Sirefef, Kryptik, or generic trojans.
During analysis of the 2012 samples, the malware was found to inject a hidden library into Explorer.exe, and the analyst used GMER and LordPE to carve the DLL from memory after TDSS Killer, Avast Rootkit utility, and RootRepeal failed to detect or remove it. Strings from the dumped DLL indicated ZeroAccess peer-to-peer functionality and hidden storage paths under RECYCLER and $Recycle.Bin.
A fresh batch of five ZeroAccess/Sirefef samples was analyzed, and the infected host was observed communicating with numerous external IPs consistent with active peer-to-peer command-and-control activity. The malware used lure filenames themed around pornography, free videos, Flash Player updates, and generic readme executables.
The tutorial analysis cited in the Contagio post said further analysis and network forensics linked ZeroAccess hosting and origin infrastructure to the Ecatel Network and associated it with the Russian Business Network. This represented an attribution-related finding about the malware’s supporting infrastructure.
A Contagio post highlighted Giuseppe Bonfa’s four-part reverse-engineering tutorial on ZeroAccess/Max++/Smiscer, covering the user-mode dropper, kernel stealth driver, process injection, and tracing the malware’s origins. The post also stated that ZeroAccess was being used as a stealth platform for FakeAV and potentially credential- or financial-theft payloads.
A 2011 ZeroAccess sample named "MaxRootkit_2011_1.exe" was submitted to VirusTotal and detected by 25 of 43 antivirus engines. Multiple vendors classified it as Sirefef, Trojan, dropper, worm, or FakeAlert malware.
An earlier ZeroAccess/Max++ installer sample, "Max++ downloader install_2010.exe," was submitted to VirusTotal, where it was detected by 40 of 43 antivirus engines. The sample was described as being distributed via FakeAV campaigns including Antivirus2010.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 181 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
contagiodump.blogspot.com
Open sourcecontagiodump.blogspot.com
Open sourceresources.infosecinstitute.com
Open sourceresources.infosecinstitute.com
Open sourceresources.infosecinstitute.com
Open sourceresources.infosecinstitute.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.