RE: info reg Zeus bot detection and analysis

Younger Tyler <[email protected]> Wed, 19 May 2010 16:06:34 -0400
Newsgroups gmane.comp.security.honeypots
Message-ID <[email protected]>
Any tips on how to selectively get infected with Zeus?


You can find the latest Zeus variants here http://www.malwaredomainlist.com=
/mdl.php

Tyler

-----Original Message-----
From: [email protected] [mailto:[email protected]] On=
 Behalf Of Michele Zoerb
Sent: Wednesday, May 19, 2010 11:39 AM
To: Mayank.2.Bhatnagar; honeypot honeypot
Subject: RE: info reg Zeus bot detection and analysis

Interesting thoughts as I am just starting the same type of project.  I wan=
t to get infected by Zeus and perform some analysis.  I have a closed envir=
onment, but didn't think that detecting a virtual environment would be an i=
ssue for the bot.  I will put my VMconverter onto a separate machine and cl=
one from there.

Any tips on how to selectively get infected with Zeus?

Thanks,
Chele

-----Original Message-----
From: [email protected] [mailto:[email protected]] On=
 Behalf Of Mayank.2.Bhatnagar
Sent: Wednesday, May 19, 2010 4:12 AM
To: honeypot honeypot
Subject: info reg Zeus bot detection and analysis

Hi everyone,

We are able to collect several samples of Zeus bot and there are many varia=
nts of the same.
However when we try to analyse it in our sandbox and closed environment, we=
 are not able to get any activity.
There are several reports available, which are for same md5sum sample but s=
till after much of analysis and triggering attempts, either the malicious s=
ample dosnt trigger or if it does, it doesn't show any network activity.

What could be the reason? Where is the catch?? We have referred Zeus tracke=
r sites (https://zeustracker.abuse.ch/blocklist.php), threatExpert reports =
but precisely what kind of analysis should be done and what environment cre=
ated to analyse these setups.

We found that Vmware/Virtual setups may have been getting detected, but wha=
t abt a live sandbox environment. Why is the malicious exe not triggering t=
here?? Where are we missing?

Anyone having pointers, suggestions...please suggest.
Thanks a lot,

Regards,
Mayank,
India


The information contained in this e-mail and any accompanying documents is =
intended for the sole use of the recipient to whom it is addressed, and may=
 contain information that is privileged, confidential, and prohibited from =
disclosure under applicable law. If you are not the intended recipient, or =
authorized to receive this on behalf of the recipient, you are hereby notif=
ied that any review, use, disclosure, copying, or distribution is prohibite=
d. If you are not the intended recipient(s), please contact the sender by e=
-mail and destroy all copies of the original message. Thank you.