427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet298/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   294   295   296   297   298   299   300   301   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
Using Sandbox Tools for Botnets • Chapter 10
365
427_Botnet_10.qxd 1/9/07 3:06 PM Page 365


has detected (by inspecting the traffic) that the protocol used in this connec-
tion is IRC. Because of that it was able to retrieve all the protocol-dependent
IRC data from the traffic stream:

The parameter of the user command is 
XP-DEU 0 0
:[XP|DEU|P|00|gcoDZaUz],
which means that the username is
XP-DEU
, the IRC 
usermode
is 0 and the 
realname
is
:[XP|DEU|P|00|gcoDZaUz].

The nickname is 
[XP|DEU|P|00|gcoDZaUz].

The channel ##tibia2## is joined using the password 
tibiablows
.

The channel topic is 
:.scan.stop -s;.scan.start NETAPI 40 -a -s;
.scan.start NETAPI 40 -b –s
.

From the name of the attribute 
topic_deleted
you can see that the
channel topic is received but in fact not being passed to the malware;
the CWSandbox can be configured in multiple ways to prevent a
further processing of received bot commands.
The last entries of the analysis report reveal that the malware opens a
backdoor on TCP port 1910, but it is not being connected during the analysis
run:

connectionestablished="0" socket="1392"/>

That is it for the second process of this malware analysis. We have seen the
most essential operations of such simple bot applications: After it has copied
itself to the Windows directory and started, this new instance deletes the orig-
inal malware file, sets up an autostart registry entry, opens a backdoor, resolves
the domain name of its C&C server, connects to this server, and joins the
correct channel. Because we did not let the channel topic pass to the malware
receiving function, its functionality stops there. An extract of the transformed
HTML report of this analysis appears in Table 10.1, showing the analysis only
for the second process. Again, some unimportant parts have been removed to
reduce its length.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   294   295   296   297   298   299   300   301   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish