info reg Zeus bot detection and analysis

"Mayank.2.Bhatnagar" <[email protected]> Wed, 19 May 2010 16:42:02 +0530
Newsgroups gmane.comp.security.honeypots
Message-ID <51B335651C9A0C4EA520D47F23A580B4143506D3BC@SINNODMBX001.TechMahindra.com>
Hi everyone,

We are able to collect several samples of Zeus bot and there are many varia=
nts of the same.
However when we try to analyse it in our sandbox and closed environment, we=
 are not able to get any activity.
There are several reports available, which are for same md5sum sample but s=
till after much of analysis and triggering attempts, either the malicious s=
ample dosnt trigger or if it does, it doesn't show any network activity.

What could be the reason? Where is the catch?? We have referred Zeus tracke=
r sites (https://zeustracker.abuse.ch/blocklist.php), threatExpert reports =
but precisely what kind of analysis should be done and what environment cre=
ated to analyse these setups.

We found that Vmware/Virtual setups may have been getting detected, but wha=
t abt a live sandbox environment. Why is the malicious exe not triggering t=
here?? Where are we missing?

Anyone having pointers, suggestions...please suggest.
Thanks a lot,

Regards,
Mayank,
India