427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet313/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   309   310   311   312   313   314   315   316   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
Using Sandbox Tools for Botnets • Chapter 10
381
427_Botnet_10.qxd 1/9/07 3:06 PM Page 381







Finally, a lot of malware tries to steal sensitive data from the local host.
This can be done by installing a keylogger or by directly accessing the places
where such data is stored.The explicit process of keylogging is not detected
by current version of CWSandbox and will be added as a new feature in
coming releases. Nevertheless, because some files need to be installed as an
autostart application or as a service or driver for that purpose, this will
become obvious by examining the report. If the malware tries to read the data
directly from its storage location, this could happen in several ways, depending
on that location. Examples for retrieving dialup network configuration data
and contents of address books for several mail clients are these (note that
some malware uses 

and other malware uses 

or even

to check for the existence of such files):


Anwendungsdaten\Microsoft\Network\Connections\Pbk\*.pbk"/>
Data\Qualcomm\Eudora\NNdbase.txt" creationdistribution="OPEN_EXISTING"/>
Data\The Bat!\TheBat.ABD" creationdistribution="OPEN_EXISTING"/>

In Windows 2000 the 
Protected Storage Service
was introduced.This is a ser-
vice for storing sensitive data such as passwords or private keys in a protected
and encrypted way. It is used to save the passwords that have been entered in
Internet Explorer or Microsoft Outlook and Outlook Express, but it also can
be used by any other user application to protect its sensitive data. For that
reason it is an open treasure chest for each malicious application. CWSandbox
detects all accesses to this Protected Storage and reports them in a

.

An example of such a report follows:

subtypename="Subscriptions"/>

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   309   310   311   312   313   314   315   316   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish