427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet314/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   310   311   312   313   314   315   316   317   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
382
Chapter 10 • Using Sandbox Tools for Botnets
427_Botnet_10.qxd 1/9/07 3:06 PM Page 382


subtypename="INETCOMM Server Passwords"/>
subtypename="INETCOMM Server Passwords"
itemname="mail.microsoft.com5E3655B0"/>

subtypename="Identities"/>
subtypename="Identities" itemname="IdentitiesPass"/>

subtypename="Internet Explorer"/>
subtypename="Internet Explorer"
itemname="http://www.gmx.net/de/:StringData"/>
Bot-Related 
Findings of Our Live Sandbox
We have been running a live sandbox system at the University of Mannheim, in
Germany, which consists of four CWSandbox hosts and uses a MySQL database
as repository. New samples can be submitted via the Web interface at
www.cwsandbox.org, but many people use scripts to transmit files automati-
cally. In the last few months we have successfully analyzed a total of 11,965
unique malware samples. Inside this set, CWSandbox has detected 1283 pro-
grams that have successfully established an IRC connection to a remote host.
From those, 108 did not follow an RFC conforming protocol but a slightly
modified variant instead. Furthermore, of the others, 40 did send a TCP packet
with data such as 
NICK (null)abcdef
without having a connection established.
Those probably are badly designed applications
1
or some other unforeseen error
occurred during their execution. Anyway, we can assume that these also are
applications that implement some form of IRC communication. Finally, 492 of
the rest tried to connect to a TCP server on port 6665, 6666, or 6667, which
lets us assume that they were also going to initiate an IRC session. So, from the
11,965 samples, 1815 tried to or succeeded in establishing an IRC connection
and, therefore, can be seen as bots or, at least, as malware that contains bot-like
behavior.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   310   311   312   313   314   315   316   317   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish