Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Editor Blogs > Security

May 8th, 2012, 09:55 GMT · By

BLOG

Botnet Source Code Reveals Anti-Analysis Functions

SHARE:

Adjust text size:


The bot is programed to check for the presence of network analysis tools Enlarge picture - The bot is programed to check for the presence of network analysis tools
A few days ago, security researchers from McAfee came across the source code of a botnet on Pastebin, the popular paste site. After analyzing the code, experts have found a couple of interesting features that are worth mentioning.

While the installation process and the way it communicates with its command and control server are fairly standard for a bot, the anti-analysis features make it stand out from the crowd.

To ensure that their botnet can’t be investigated by security solutions providers, the creators of the malicious element included a couple of mechanisms that detect the presence of a sandbox environment or a network monitoring tool, such as Wireshark, SysAnlyzed, or OllyDbg.

In case the aforementioned pieces of software are detected, the bot terminates its process. This way the botnet operators can make sure that researchers can’t come up with countermeasures.

Fortunately, the source code offers great insight on a botnet’s inner workings.
FILED UNDER:
botnet
bot
source code

TELL US WHAT YOU THINK:

1,501 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Google Notifies ZeuS Botmasters That Microsoft Is Coming for Them

Flashback Mac OS X Trojan Earns Its Masters $10,000 (€ 7,600) Each Day

Cybercriminals Brag About the Success of DDOS Services

Price of Malware Drops, SpyEye Botnet Available for $150 (€114)

Nitol DDOS Botnet Coded in a Hurry, Experts Say

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM