A malicious copycat of the Virustotal website has emerged that aims to infect visitors with malware to build a botnet.
The site included JavaScript that installed a worm (Worm.MSIL.Arcdoor.ov) which collects victim machine information for a command and control server, according to Kaspersky Lab.
The botnet performs DDoS attacks including synflood, httpflood, udpflood and icmpflood, researcher Jorge Mieres wrote in a blog.
The real Virustotal website is a free malware detection service.
