<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; P2P</title>
	<atom:link href="http://www.honeynet.it/tag/p2p/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Wed, 11 Jan 2012 11:44:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>ZeuS P2P variant analysis</title>
		<link>http://www.honeynet.it/malware/zeus-p2p-variant-analysis</link>
		<comments>http://www.honeynet.it/malware/zeus-p2p-variant-analysis#comments</comments>
		<pubDate>Thu, 05 Jan 2012 14:02:24 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=444</guid>
		<description><![CDATA[
[..]In the new version of the Trojan, the authors focus on eliminating the weakest link – a centralized system of information distribution. Previous versions of Zeus were based on one (or few) predefined addresses which were used for botnet management. This allowed for relatively easy tracking and blocking of servers, thus rendering the botnet useless. [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>[..]In the new version of the Trojan, the authors focus on eliminating the weakest link – a centralized system of information distribution.<br />
Previous versions of Zeus were based on one (or few) predefined addresses which were used for botnet management. This allowed for relatively easy tracking and blocking of servers, thus rendering the botnet useless. However, the analysed variant of the Trojan used two new channels of communication to receive orders (figure on right):</p>
<ol>
<li>Communication in a peer-to-peer network</li>
<li>Domain names Generation Mechanism</li>
</ol>
<p>This variant has been analyzed to some extent by other researchers before – there is information on the web on the new variant of Zeus (eg <a href="http://www.abuse.ch/?p=3499"> abuse.ch </a>), however – based on our knowledge – previous research has focused on registering and monitoring traffic to Zeus domains. <strong>In our work we focus on understanding the P2P network communication mechanisms, mapping out the network, and monitoring the exchange of information in this particular network.</strong> [..]<strong><br />
</strong></p></blockquote>
<p>via <a href="http://www.cert.pl/news/4711/langswitch_lang/en">CERT Polska » Blog Archive » ZeuS – P2P+DGA variant – mapping out and understanding the threat</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/malware/zeus-p2p-variant-analysis/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>P2P Version of Zeus Botnet Appears &#124; threatpost</title>
		<link>http://www.honeynet.it/botnet/p2p-version-of-zeus-botnet-appears-threatpost</link>
		<comments>http://www.honeynet.it/botnet/p2p-version-of-zeus-botnet-appears-threatpost#comments</comments>
		<pubDate>Thu, 20 Oct 2011 11:51:13 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=433</guid>
		<description><![CDATA[
A new version of the Zeus malware has appeared, and this does not seem to be a minor upgrade, but a major custom version of the Trojan, which now sports a P2P capability that does away with the use of the domain-generation algorithm used in earlier versions and instead uses a hardcoded list of IP [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>A new version of the Zeus malware has appeared, and this does not seem to be a minor upgrade, but a major custom version of the Trojan, which now sports a P2P capability that does away with the use of the domain-generation algorithm used in earlier versions and instead uses a hardcoded list of IP addresses to provide infected PCs with new software and config files. This is a throwback to the way the malware used to behave, but it comes with a twist: There no longer is a master URL that infected machines contact to get updates, making it much more difficult to track the Trojan&#8217;s activities.</p>
<p>[..]</p>
<p>The version of Zeus discovered recently by the Swiss Abuse.ch group implements this strategy through the inclusion of a built-in list of IP addresses that each newly infected PC should try to contact in order to receive instructions and updated configuration files. The new bot does this by sending out UDP packets on a high-numbered port, looking for like-mided peers. If one responds, the new bot will get a new list of IPs of other infected PCs in the botnet. The version of Zeus also can remotely check which version of the malware is running on remote PCs and download an updated version, if necessary, the researchers said in a blog post analyzing the Zeus update.</p>
<p>[..]</p>
<p>&#8220;At first glance these are bad news. But fortunately the new mechanism also has benefits: There is just one ZeuS C&amp;C active at the same time, so every time the domain name gets suspended/terminated, the criminals have to push out a new config file.&#8221;</p></blockquote>
<p>via <a href="http://threatpost.com/en_us/blogs/p2p-version-zeus-botnet-appears-101111">P2P Version of Zeus Botnet Appears | threatpost</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/p2p-version-of-zeus-botnet-appears-threatpost/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TDL4 – High sophisticated botnet unveiled</title>
		<link>http://www.honeynet.it/uncategorized/tdl4-%e2%80%93-high-sophisticated-botnet-unveiled</link>
		<comments>http://www.honeynet.it/uncategorized/tdl4-%e2%80%93-high-sophisticated-botnet-unveiled#comments</comments>
		<pubDate>Fri, 01 Jul 2011 08:22:08 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[TDSS]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=418</guid>
		<description><![CDATA[
The fact that TDL-4 code shows active development — a rootkit for 64-bit systems, the malware running prior to operating system start launches, the use of exploits from Stuxnet’s arsenal, P2P technology, its own ‘antivirus’ and a lot more — place TDSS firmly in the ranks of the most technologically sophisticated, and most complex to [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The fact that TDL-4 code shows active development — a rootkit for 64-bit systems, the malware running prior to operating system start launches, the use of exploits from Stuxnet’s arsenal, P2P technology, its own ‘antivirus’ and a lot more — place TDSS firmly in the ranks of the most technologically sophisticated, and most complex to analyze, malware.</p></blockquote>
<p>via <a href="http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot">TDL4 – Top Bot &#8211; Securelist</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/tdl4-%e2%80%93-high-sophisticated-botnet-unveiled/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cracking Down on Botnets &#8211;  Microsoft  against Waledac</title>
		<link>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets</link>
		<comments>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets#comments</comments>
		<pubDate>Thu, 25 Feb 2010 20:15:36 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[waledac]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=176</guid>
		<description><![CDATA[
The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy. [..] In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy.</p>
<p>[..]</p>
<p>In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to Waledac were directed to Hotmail accounts alone, including offers and scams related to online pharmacies, imitation goods, jobs, penny stocks and more.</p>
<p>[..]</p>
<p>This action has quickly and effectively cut off traffic to Waledac at the “.com” or domain registry level, severing the connection between the command and control centers of the botnet and most of its thousands of zombie computers around the world.</p></blockquote>
<p>via <a href="http://blogs.technet.com/microsoft_blog/archive/2010/02/25/cracking-down-on-botnets.aspx">The Official Microsoft Blog – Cracking Down on Botnets</a>.</p>
<p>Well done.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

