Minotaur Malware Analysis Blog

Malware

Anti-Malware DNS System Outage

by on May.09, 2012, under Malware

We are aware that the anti-malware DNS comparison engine is offline. We are working on a new version, and if you have any DNS vendors you would like to add to our list, please email info@novcon.net. We hope to restore this service shortly.

Leave a Comment :, more...

Backchannel Tracking

by on Jul.03, 2011, under Analytics, Malware, Minotaur

Minotaur has added several new features of the last couple weeks. Most of these features have to do with backchannels. Backchannels are network communications that malware uses to “call home”. These communications can be anything from retrieving new commands and configurations to simple lookups of public information from public sources. Minotaur keeps track of all communications that take place during the execution of malware in the sandbox. It then correlates all of these communications with each other and produces a list of the top destinations of this traffic. Minotaur also produces a map of all communications that take place during the execution of the sample. Below is an example of such a map.

These capabilities are very much still a work in progress. We hope to soon provide much more information about each IP address and each communication. In the meantime we are building a database of all known back channels that Minotaur observes. The first fruits of this database can be seen in the link below.

BackChannels

Leave a Comment more...

If a picture is worth a thousand words, then…

by on Jun.22, 2011, under Analytics, Malware, Minotaur

…what’s 15,000 pictures worth?

Yup, minotaur now saves a video of each (relevant) sample processed via it’s cuckoo VMs.

What does it look like? WHy not check out a few samples with videos:

Fake AV
Hupigon

And for some old school mayhem:
Joke.Program

The system is automatically recording new samples as they come in as well as back-filling samples as it has time.

Leave a Comment more...

KIS 2012 vs NIS 2012 Beta (Video)

by on Jun.20, 2011, under Malware

Languy99 has published a video comparison of malware detection capabilities or Kaspersky 2012 vs. Norton 2012 Beta

 

Leave a Comment more...


Week-in-Malware Review

by on Apr.12, 2011, under Malware

  • Today is the record for Patch Tuesdays, with 17 bulletins and 64 vulnerabilities
Leave a Comment more...

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!