RE: info reg Zeus bot detection and analysis
Younger Tyler <[email protected]> Wed, 19 May 2010 16:06:34 -0400
| Newsgroups | gmane.comp.security.honeypots |
|---|---|
| Message-ID | <[email protected]> |
Any tips on how to selectively get infected with Zeus? You can find the latest Zeus variants here http://www.malwaredomainlist.com= /mdl.php Tyler -----Original Message----- From: [email protected] [mailto:[email protected]] On= Behalf Of Michele Zoerb Sent: Wednesday, May 19, 2010 11:39 AM To: Mayank.2.Bhatnagar; honeypot honeypot Subject: RE: info reg Zeus bot detection and analysis Interesting thoughts as I am just starting the same type of project. I wan= t to get infected by Zeus and perform some analysis. I have a closed envir= onment, but didn't think that detecting a virtual environment would be an i= ssue for the bot. I will put my VMconverter onto a separate machine and cl= one from there. Any tips on how to selectively get infected with Zeus? Thanks, Chele -----Original Message----- From: [email protected] [mailto:[email protected]] On= Behalf Of Mayank.2.Bhatnagar Sent: Wednesday, May 19, 2010 4:12 AM To: honeypot honeypot Subject: info reg Zeus bot detection and analysis Hi everyone, We are able to collect several samples of Zeus bot and there are many varia= nts of the same. However when we try to analyse it in our sandbox and closed environment, we= are not able to get any activity. There are several reports available, which are for same md5sum sample but s= till after much of analysis and triggering attempts, either the malicious s= ample dosnt trigger or if it does, it doesn't show any network activity. What could be the reason? Where is the catch?? We have referred Zeus tracke= r sites (https://zeustracker.abuse.ch/blocklist.php), threatExpert reports = but precisely what kind of analysis should be done and what environment cre= ated to analyse these setups. We found that Vmware/Virtual setups may have been getting detected, but wha= t abt a live sandbox environment. Why is the malicious exe not triggering t= here?? Where are we missing? Anyone having pointers, suggestions...please suggest. Thanks a lot, Regards, Mayank, India The information contained in this e-mail and any accompanying documents is = intended for the sole use of the recipient to whom it is addressed, and may= contain information that is privileged, confidential, and prohibited from = disclosure under applicable law. If you are not the intended recipient, or = authorized to receive this on behalf of the recipient, you are hereby notif= ied that any review, use, disclosure, copying, or distribution is prohibite= d. If you are not the intended recipient(s), please contact the sender by e= -mail and destroy all copies of the original message. Thank you.