Minotaur Malware Analysis Blog

Tag: Updates

New HTTP and DNS deep analysis

by on May.24, 2012, under Minotaur

 

Minotaur has gotten a few new upgrades. Most notably on the web frontend is the addition of two new sections in the sample reports. Now, each sample’s traffic capture will be further analyzed for the URIs accessed and all DNS requests and responses.

One hope is that this analysis will provide for a rich dataset for further analytics based on URI patterns, and DNS anomalies.

As an example, the following backchannel requests popped up from sample 6da34a083feef6f9553e492e10537ca5:

Host Port URI Method
imperial-scape.org 80 /Comune.php?logdata=Infected GET
imperial-scape.org 80 /Comune.php?logdata=Executed%20payload GET
imperial-scape.com 80 /Comune.php?logdata=RAR%20archives%20infected GET
imperial-scape.com 80 /Comune.php?logdata=Infected GET
imperial-scape.com 80 /Comune.php?logdata=Executed%20payload GET

Oh how I wish they all were so easy they put “logdata=infected” and “logdata=Executed%20payload” in the URI.

Leave a Comment :, , more...

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!