Vol. 1 No 1 (2015): Proceedings of Botconf 2015
Papiers courts de conférence

Make It Count: an Analysis of a Brute-forcing Botnet

Veronica Valeros
CISCO

Publiée 2016-02-29

Comment citer

Valeros, V. . (2016). Make It Count: an Analysis of a Brute-forcing Botnet. Le Journal De La Cybercriminalité Et Des Investigations Numériques, 1(1), 55-59. https://doi.org/10.18464/cybin.v1i1.5

Télécharger la référence bibliographique

Résumé

The smallest element in a botnet is a bot. The behavior of a bot can change dynamically based on the decision of the botmaster. Commonly driven by profit, bots are expected to be profitable. If an infected bot does not fulfill the expectations, the botmaster can instruct the bot to switch it's behavior to serve a better purpose. This paper presents a detailed analysis of a network traffic capture of a machine originally infected by a Gamarue variant. The analysis will uncover the behavior of the bot since the initial infection, inactivity period, delivery of a new payload and the following switch of behavior of the bot. The paper will analyze the infection in detail, including the horizontal brute-forcing activity affecting thousands of WordPress websites. The goal of the paper is to show a concrete example of a bot performing brute-forcing, analyze it, identify the mechanisms used and indicators of compromise that will help detect it.