427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet318/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   314   315   316   317   318   319   320   321   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
Using Sandbox Tools for Botnets • Chapter 10
387
427_Botnet_10.qxd 1/9/07 3:06 PM Page 387



The DLL installs API hooks for all important functions of the
Windows API.

If a new process is started by the malware or if an existing one is
infected, this process is also monitored.

After a customizable time, all monitored processes are terminated.

A high-level summarized analysis report is created of all the mon-
itored actions.

The network traffic is examined, important Web protocols
(HTTP, FTP, IRC, and so on) are recognized, and all relevant pro-
tocol data (username, password, and the like) is reported.
Automated Analysis Suite (AAS) is a tool for automatic collection
and analysis of malware:

AAS uses a database to store malware samples and the corre-
sponding created analysis reports.

AAS integrates the honeypot tool 
Nepenthes
for automatic mal-
ware collection.

Additionally, malware can be submitted via a PHP-based Web
interface.

AAS embeds CWSandbox for automatic analysis.
Examining a Sample Analysis Report
The CWSandbox analysis report of Backdoor.IRCBot.S
(BitDefender), BackDoor.Generic4.VT (AVG), and
Backdoor.Win32.IRCBot.yc (Kaspersky) is presented.
This binary is a simple bot application that shows most of the
common actions performed by this malware class:

The initial file copies itself into the Windows Directory and starts
this copy.

The copy first deletes the initial malware file.

Then a mutex is created to prevent multiple parallel instances.

An autostart registry key is created.
www.syngress.com
388

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   314   315   316   317   318   319   320   321   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish