427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet308/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   304   305   306   307   308   309   310   311   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
376
Chapter 10 • Using Sandbox Tools for Botnets
427_Botnet_10.qxd 1/9/07 3:06 PM Page 376


outgoing TCP connection and/or DNS requests as evidence of such an
update request. If you are lucky, the reloading of code or data is done via
HTTP or FTP. In that case the report would contain outputs like this:

remoteport="80" protocol="HTTP" connectionestablished="1" socket="2004">




remoteport="80" protocol="HTTP" connectionestablished="1" socket="2004">




remoteport="80" protocol="HTTP" connectionestablished="1" socket="2040">





As you can see, there are several .exe files downloaded from the same host,
194.187.45.55. In fact, for this particular malware (NOD32 calls it
Win32/TrojanDownloader.Adload.NAN Trojaner
), a total of 10 (!) different .exe
files are reloaded. After the malware has downloaded them to the local disk,
they are executed:
showwindow="SW_MAXIMIZE" apifunction="CreateProcessW" successful="1"/>
showwindow="SW_MAXIMIZE" apifunction="CreateProcessW" successful="1"/>
showwindow="SW_MAXIMIZE" apifunction="CreateProcessW" successful="1"/>
Sometimes the malware does not use one of the standard Web protocols
to reload data.Then it is harder to determine the fact that something exe-
cutable or configuration data is retrieved. Again, the CWSandbox feature to
log all communication data will help in this case. In any event, you should use
the option 
STORE_CREATED_FILES
, by which you will get a copy of

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   304   305   306   307   308   309   310   311   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish