{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T22:03:28Z","timestamp":1757541808102,"version":"3.40.3"},"publisher-location":"Cham","reference-count":21,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319053011"},{"type":"electronic","value":"9783319053028"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-05302-8_25","type":"book-chapter","created":{"date-parts":[[2014,3,20]],"date-time":"2014-03-20T14:31:24Z","timestamp":1395325884000},"page":"408-425","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["On the Reverse Engineering of the Citadel Botnet"],"prefix":"10.1007","author":[{"given":"Ashkan","family":"Rahimian","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Raha","family":"Ziarati","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stere","family":"Preda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,3,21]]},"reference":[{"key":"25_CR1","volume-title":"Practical Malware Analysis, The Hands-On Guide to Dissecting Malicious Software","author":"M Sikorski","year":"2012","unstructured":"Sikorski, M., Honig, A.: Practical Malware Analysis, The Hands-On Guide to Dissecting Malicious Software. No Starch Press, San Francisco (2012)"},{"key":"25_CR2","volume-title":"Gray Hat Python: Python Programming for Hackers and Reverse Engineers","author":"J Seitz","year":"2009","unstructured":"Seitz, J.: Gray Hat Python: Python Programming for Hackers and Reverse Engineers. No Starch Press, San Francisco (2009)"},{"key":"25_CR3","unstructured":"Malware Forensics Field Guide for Windows Systems: Digital Forensics Field Guides. Waltham: Syngress (2012)"},{"key":"25_CR4","volume-title":"The IDA Pro book : The Unofficial Guide to the World\u2019s Most Popular Disassembler","author":"C Eagle","year":"2011","unstructured":"Eagle, C.: The IDA Pro book : The Unofficial Guide to the World\u2019s Most Popular Disassembler. No Starch Press, San Francisco (2011)"},{"key":"25_CR5","volume-title":"Identifying Malicious Code Through Reverse Engineering (Advances in Information Security)","author":"A Singh","year":"2009","unstructured":"Singh, A.: Identifying Malicious Code Through Reverse Engineering (Advances in Information Security). Springer, New York (2009)"},{"key":"25_CR6","doi-asserted-by":"crossref","unstructured":"Binsalleeh, H., Ormerod, T., Boukhtouta, A., Sinha, P., Youssef, A., Debbabi, M., Wang, L.: On the analysis of the zeus botnet crimeware toolkit. In: International Conference on Privacy Security and Trust (PST), Ottawa (2010)","DOI":"10.1109\/PST.2010.5593240"},{"key":"25_CR7","series-title":"LNCS","first-page":"211","volume-title":"FPS 2012","author":"A Rahimian","year":"2013","unstructured":"Rahimian, A., Charland, P., Preda, S., Debbabi, M.: RESource: a framework for online matching of assembly with open source code. In: Garcia-Alfaro, J., Cuppens, F., Cuppens-Boulahia, N., Miri, A., Tawbi, N. (eds.) FPS 2012. LNCS, vol. 7743, pp. 211\u2013226. Springer, Heidelberg (2013)"},{"key":"25_CR8","unstructured":"Charland, P., Fung, B.C.M., Farhadi, M. R.: Clone search for malicious code correlation. In: ATO RTO Symposium on Information Assurance and Cyber Defense (IST-111), Koblenz (2012)"},{"key":"25_CR9","doi-asserted-by":"crossref","unstructured":"Saebjornsen, A., Willcock, J., Panas, T., Quinlan, D., Su, Z.: Detecting code clones in binary executables. In: International Symposium on Software Testing and Analysis (ISSTA), Chicago (2009)","DOI":"10.1145\/1572272.1572287"},{"key":"25_CR10","unstructured":"Sherstobitoff, R.: Inside the World of the Citadel Trojan. McAfee (2013)"},{"key":"25_CR11","unstructured":"AnhLab ASEC: Malware Analysis: Citadel. http:\/\/seifreed.es\/docs\/Citadel%20Troja%20Report_eng.pdf (December 2012). Accessed May 2013"},{"key":"25_CR12","unstructured":"Wyke, J.: The Citadel Crimeware Kit - Under the Microscope. http:\/\/nakedsecurity.sophos.com\/2012\/12\/05\/the-citadel-crimeware-kit-under-the-microscope\/ (December 2012). Accessed May 2013"},{"key":"25_CR13","unstructured":"CERT Polska: Takedown of the plitfi Citadel botnet. www.cert.pl\/PDF\/Report_Citadel_plitfi_EN.pdf (April 2013). Accessed May 2013"},{"key":"25_CR14","unstructured":"Microsoft Digital Crimes Unit: Microsoft, financial services and others join forces to combat massive cybercrime ring. http:\/\/www.microsoft.com\/en-us\/news\/Press\/2013\/Jun13\/06-05DCUPR.aspx (June 2013). Accessed June 2013"},{"key":"25_CR15","unstructured":"Vincent, J.: $${\\$}500$$ million botnet Citadel attacked by Microsoft and the FBI: Joint operation identified more than 1000 botnets, but operations continue. http:\/\/www.independent.co.uk\/life-style\/gadgets-and-tech\/news\/500-million-botnet-citadel-attacked-by-microsoft-and-the-fbi-8647594.html (June 2013). Accessed June 2013"},{"key":"25_CR16","unstructured":"List of Domain Names by Registry (Citadel). http:\/\/botnetlegalnotice.com\/citadel\/files\/Compl_App_A.pdf (June 2013)"},{"key":"25_CR17","unstructured":"Milletary, J.: Citadel Trojan Malware Analysis. Dell SecureWorks (2012)"},{"key":"25_CR18","unstructured":"Immunity Debugger: The Best of Both Worlds, Immunity. http:\/\/www.immunityinc.com\/products-immdbg.shtml (2013)"},{"key":"25_CR19","unstructured":"IDA Pro: Multi-processor Disassembler and Debugger, Hex-Rays. https:\/\/www.hex-rays.com\/products\/ida\/debugger\/index.shtml (2013)"},{"key":"25_CR20","unstructured":"The Volatility Framework: Volatile Memory (RAM) Artifact Extraction Utility Framework, Volatile Systems. https:\/\/www.volatilesystems.com\/default\/volatility (2013)"},{"key":"25_CR21","doi-asserted-by":"crossref","unstructured":"Bonfante, G., Marion, J., Sabatier, F., Thierry, A.: Code Synchronization by morphological analysis. In: International Conference on Malicious and Unwanted Software (MALWARE), Washington (2012)","DOI":"10.1109\/MALWARE.2012.6461016"}],"container-title":["Lecture Notes in Computer Science","Foundations and Practice of Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-05302-8_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,19]],"date-time":"2023-01-19T17:16:56Z","timestamp":1674148616000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-05302-8_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319053011","9783319053028"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-05302-8_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]},"assertion":[{"value":"21 March 2014","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}