- 1、本文档共47页,可阅读全部内容。
- 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
2014-2.10-Chinese-Chicken-Multiplatform-DDoS-Botnets
Chinese Chicken:
Multiplatform DDoS
botnets
Peter Kálnai
@pkalnai
Jaromír Ho?ej?í
@JaromirHorejsi
Dec 3nd – Dec 5th 2014
Nancy, France
Outline
? Timeline (+References)
? Binaries, common characteristics
? Advertisements
? Infection vector
? Flooding tools/Trojans:
? Elknot Bill Gates
? Mr. Black
? IptabLes/IptabLex
? XOR.DDoS
? gh0st RAT
? Statistics and victim preference
? Summary
Timeline (+ References)
? (Edwards, Nazario (ArborNetworks): “A Survey of Contemporary Chinese DDoS
Malware”, VB2011, Barcelona)
? First builder of Linux flooding bot received at our backend in November 2013
? Secure Honey honeypot: “Trojan Horse Uploaded”, November 2013
? MalwareMustDie! : “Lets be more serious about (mitigating) DNS Amp ELF hack
attack”, December 2013 (Linux:Elknot)
? Sempersecurus: “Another look at a cross-platform DDoS botnet”, Dec 2014
? ValdikSS – “Исследуем Linux Botnet ?BillGates?”, February 2014
? Associating Elknot name with previous research, March 2014
? Dr. Web – “DDoS Trojans attack Linux”, May 2014 (+Linux:MrBlack)
Timeline (+ References)
? Kaspersky: “Versatile DDoS Trojan for Linux”, July 2014
? Kaspersky: “elasticsearch Abuse on Amazon Cloud and More for DDoS and
Profit”, July 2014 (Infection chain)
? Prolexic (Akamai): “IptabLes/IptabLex DDoS Bots”, September 2014
? MMD!: “Tango down report of OP China ELF DDoSer”, September 2014
? MMD!: “MMD-0026-2014 - Router Malware Warning | Reversing an ARM arch
ELF AES.DDoS”, September 2014 (UPX-packed ELF:MrBlack)
? Prolexic (Akamai): “Spike DDoS Toolkit”, October 2014 (ELF:MrBlack)
? ESET: “G20 2014 Summit Lure used to target Tibetan activists”, November
2014 (Windows gh0st RAT)
? MMD!: “China ELF botnet malware infection distribution scheme
unleashed”, November 2014
Infection chain
? Attackers
? build ELF malware using a
customized builder
? start HTTP File Server (HFS) to
host the previously built
malicious binaries
? run port scanners on
您可能关注的文档
- 15秋学期南开《大学英语(三)》在线作业.doc
- 16-20 Jupiter mass RV companion orbiting the brown dwarf candidate ChaHa8.pdf
- 16.3 人体的激素调节 课件 (苏科版八年级上) (17张ppt).ppt
- 16.6 Methodology and Experimental Verification for Substrate Noise Reduction in CMOS Mixed-.pdf
- 16sentences.doc
- 16fin+and+tube+heatexchanger.pdf
- 16秋学期100分《大学英语(二)》在线作业.pdf
- 17-基于Matlab-simulink直驱型永磁风力发电机控制系统仿真研究.doc
- 17春北航《flash制作基础》在线作业二.doc
- 18钙钛矿方法学science.pdf
文档评论(0)