spam - icir.org

33

Upload: others

Post on 12-Nov-2021

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Spam - icir.org
Page 2: Spam - icir.org
Page 3: Spam - icir.org
Page 4: Spam - icir.org
Page 5: Spam - icir.org
Page 6: Spam - icir.org
Page 7: Spam - icir.org
Page 8: Spam - icir.org
Page 9: Spam - icir.org
Page 10: Spam - icir.org
Page 11: Spam - icir.org
Page 12: Spam - icir.org
Page 13: Spam - icir.org
Page 14: Spam - icir.org
Page 15: Spam - icir.org
Page 16: Spam - icir.org
Page 17: Spam - icir.org
Page 18: Spam - icir.org
Page 19: Spam - icir.org

If we control these …

… we can monitor & influence these

Page 20: Spam - icir.org
Page 21: Spam - icir.org

Types of Storm C&C Messages

•  Activation (report from bot to botmaster) •  Email address harvests •  Spamming instructions •  Delivery reports •  DDoS instructions •  FastFlux instructions •  HTTP proxy instructions •  Sniffed passwords report •  IFRAME injection/report

Page 22: Spam - icir.org

Spam campaign mechanics

TCP

HTTP

HTTP proxies

Workers

Proxy bots

Botmaster

Page 23: Spam - icir.org

Campaign mechanics: harvest

TCP

HTTP

HTTP proxies

Workers

Proxy bots

Botmaster

@ @ @ @

@

@ @ @

Page 24: Spam - icir.org
Page 25: Spam - icir.org

Campaign mechanics: spamming

TCP

HTTP

HTTP proxies

Workers

Proxy bots

Botmaster

Page 26: Spam - icir.org
Page 27: Spam - icir.org
Page 28: Spam - icir.org

Campaign mechanics: spamming

TCP

HTTP

HTTP proxies

Workers

Proxy bots

Botmaster

Page 29: Spam - icir.org
Page 30: Spam - icir.org
Page 31: Spam - icir.org
Page 32: Spam - icir.org

Campaign mechanics: reporting

TCP

HTTP

HTTP proxies

Workers

Proxy bots

Botmaster

Page 33: Spam - icir.org