Jaime Blasco Blog


Malware: Troyak-AS and Peer activity
Sun, 14 Mar 2010

Last week Troyak-AS has been taken offline. The number of Zeus C&C servers has been decreasing steeply because of the coordinated operation.

Here you can find a list of AS50215 Troyak-as peers that conform the neighborhood of one of the most active cybercrime networks.

I want to share with you some graphs of these peers that shows the malicious activity of some of the AS's involved on this network during Q1 of 2010.

The data has been extracted from one of Alienvault sandnets.


AS-42229 MARIAM-AS PP MariamAS-44107 PROMBUDDETAL-AS Prombuddetal LLCAS-47560 VESTEH-NET-as Vesteh LLC
AS-42229AS-42229AS-42229
AS-50369 VISHCLUB-as Kanyovskiy AndriyAS-5577 ROOT SAAS-8342 RTCOMM-AS RTComm.RU Autonomous System
AS-50369AS-5577AS-8342

posted at: 21:29 | path: /Malware | permanent link to this entry | 3 comments | malware, visualization, Zeus, Botnet



* Posted by Andreas Rauer at Mon Apr 5 22:28:46 2010
Hi, is there a legend for the different symbols out there? The diagrams look quite interesting, but without an explanation for the symbols and circles it is quite non-decipherable.

Maybe you can add some meaning for me? :-)

Kind regards & thanks in advance,
Andreas
* Posted by Jaime Blasco at Sat Apr 10 17:19:11 2010
Hi,

The red squares are the AS's, the green circles are ip addresses, the pink circles are md5's of malicious binaries and the brown triangles are antivirus names for the binaries.
* Posted by ac at Fri Jul 23 11:17:55 2010
hi,

nice blog

how you do that graphs?

BR

AC

Name:


E-mail:


URL:


Comment:


Categories

/ (34)
    Attacks/ (2)
    Exploits/ (1)
    General/ (3)
    Lua/ (1)
    Malware/ (3)
    Nessus/ (6)
        cisco/ (1)
        plugins/ (3)
    Ossim/ (9)
    Scada Security/ (2)
    Security Visualization/ (6)
        Malware/ (2)
    Vulnerability Management/ (1)



Jaime Blasco
(feel free to get in touch)
  • Mail
  • Linkedin
  • Twitter
  • Linkedin
  • Forums

Friend's blogs:
  • /blog/dk
  • /blog/juanma
  • /blog/santiago
  • /blog/pablo/




RSS




Lecture...





< March 2010 >
MoTuWeThFrSaSu
1 2 3 4 5 6 7
8 91011121314
15161718192021
22232425262728
293031    




Archives

2010-Aug
2010-Jul
2010-Mar
2010-Jan
2009-Dec
2009-Oct
2009-Sep
2009-Jul
2009-Jun
2009-Apr
2009-Mar
2009-Feb
2009-Jan
2008-Oct
2008-Aug




Tags




Made with PyBlosxom