427 Botnet fm qxd


Chapter 10 • Using Sandbox Tools for Botnets



Download 6,98 Mb.
Pdf ko'rish
bet319/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   315   316   317   318   319   320   321   322   ...   387
Bog'liq
Botnets - The killer web applications

Chapter 10 • Using Sandbox Tools for Botnets
427_Botnet_10.qxd 1/9/07 3:06 PM Page 388



Some hostnames are resolved.

A C&C server is contacted using the IRC protocol.

A listening TCP server is created for incoming connections.
Interpreting an Analysis Report
The interpretation of an analysis report was explained in detail in this
chapter.
The races and hints of the most commonly performed malicious
operations of bots are shown:

How and where does the bot install its files, and how does it
ensure that they are automatically executed on system startup?

How are new hosts found for infection, and how are they probed
for common, known security leaks that could be exploited?

How is the local host protected against new infections?

How are local security and antivirus tools found and
disabled/modified to hide the bot?

How and to what are C&C servers connected?

What are traces of other malicious operations, such as sending
spam, performing DDoS attacks, stealing sensitive data from the
local system, or installing backdoors?
Bot-Related Findings of Our Live Sandbox
Some (unrepresentative) results of the analysis of 11,965 malware
samples at the University of Mannheim, Germany, were presented in
this chapter.
We have found 1815 bot applications that use the IRC protocol (or
slight modifications of that) to communicate with IRC servers on
317 different IP addresses using 120 different TCP ports.
These 1815 bots have used 497 different password-channel
combinations, which lets us assume we have found at most 497
different botnets.
www.syngress.com
Using Sandbox Tools for Botnets • Chapter 10
389
427_Botnet_10.qxd 1/9/07 3:06 PM Page 389



Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   315   316   317   318   319   320   321   322   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish