Jump to content
sandabot

Zeus Botnet 2.1.0.1

Recommended Posts

Zeus updated style P2P, each bot is nginx

Researchers at Symantec have discovered that the new version of the Zeus / SpyEye ordinary bots can act as a command server. This greatly complicate neutralizing botnets, because before the main method of disposal a network of infected computers was blocking C & C-or server failover using a dummy C & C-server. In addition, this method of organizing peer nodes complicates the search for the owner of the botnet and the work of the service makes senseless Zeustracker. Overall, this fork, that is, the parallel version of Zues, really impressive, the authors used several new methods of protection against interception of management. Researchers say that hints at the rejection of simple C & C-peer servers in favor of models appeared in the last build of Zeus at the end of 2011. The new version of this line continued: P2P botnet uses a network to gather information and improve survival. Previously transmitted between nodes list C & C-servers, and in the case of loss of communication with a network of switches to the next in the list. Now C & C-servers disappeared from the system: commands directly receives one of the nodes in P2P-networks and distributes them over the network. Bots have learned to receive from each other team, configuration files, executables. The figure shows a scheme of the old and new versions of Zeus . Another interesting innovation was a shift towards communication on UDP, rather than TCP. In the previous version only used homemade UDP-handshake. If successful, the exchange bots and other configuration files for TCP. Now the transmission is also on UDP. The screenshots shows traffic in the old and new variants of Zeus .

1875b24ca1fd.jpg

Link to comment
Share on other sites

Serios consider pe cei care spun parola niste persoane "turnatoare".Lasa'l frate sa se invete sa decrypteze .Asa moca vor toti!Nici eu nus prea bun dar incet ,incet ,imi dau seama si imi dau silinta !

Ai chef sa deschizi topicuri moarte :| .

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.


×
×
  • Create New...