« Rogue makers ahead of time?
Malrus the dragon »

Web crawling for malware with a Honeypot

October 9th, 2008

 In our daily quest for malware we use different tools, though my favourite one remains a custom HoneyPot we deployed about a year ago.

The great thing about Honeypots is that they can be totally automated and deployed on a large scale. Think of a Honeypot as a bait machine, or a trap. It is meant to behave just like a regular computer, and interact with the requests it is being sent. We want to give malware authors the illusion that we are in a weak position and ready to be compromised. What they don’t know is that we are in fact listening and logging information as well as protecting ourselves from getting infected.

The result is that we are able to detect malicious web pages as well as what type of malware they are trying to push. We download the malware for further analysis and add the malicious sites to a blacklist.

 Our Honeypots are constantly crawling the web so that we can detect infected web pages in real time, before the end user does.

Below is one machine hard at work, collecting honey ;-)

Jerome

    This entry was posted on Thursday, October 9th, 2008 at 3:28 pm and is filed under Research. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    2.      by
    3.      by
    • (3) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.