Home > ParetoLogic Blogs > Malware Diaries > Web crawling for malware with a Honeypot
Reply
 
Thread Tools Display Modes
  #1  
Old 10-10-2008, 12:28 AM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default Web crawling for malware with a Honeypot

*In our daily quest for malware we use different tools, though my favourite one remains a custom HoneyPot*we deployed about a year ago.

The great thing about Honeypots is that they can be totally automated and deployed on a large scale. Think of a Honeypot as a bait machine, or a trap. It is meant to behave just like a regular computer, and interact with the requests it is being sent. We want to give malware authors the illusion that we are in a weak position and ready to be compromised. What they don't know is that we are in fact listening and logging information as well as protecting ourselves from getting infected.

The result is that we are able to detect malicious web pages as well as what type of malware they are trying to push. We download the malware for further analysis and add the malicious sites to a blacklist.

*Our Honeypots are constantly crawling the web so that we can detect infected web pages in real time, before the end user does.

Below is one machine hard at work, collecting honey ;-)



Jerome
Reply With Quote
  #2  
Old 10-11-2008, 08:51 AM
DarkClow DarkClow is offline
Junior Member
Join Date: Oct 2008
Posts: 2
Default how to do the same for my extra computer

Quote:
Originally Posted by Michael View Post
*In our daily quest for malware we use different tools, though my favourite one remains a custom <a href="http://en.wikipedia.org/wiki/Honeypot_(computing)" target="_blank">HoneyPot</a>*we deployed about a year ago.

The great thing about Honeypots is that they can be totally automated and deployed on a large scale. Think of a Honeypot as a bait machine, or a trap. It is meant to behave just like a regular computer, and interact with the requests it is being sent. We want to give malware authors the illusion that we are in a weak position and ready to be compromised. What they don't know is that we are in fact listening and logging information as well as protecting ourselves from getting infected.

The result is that we are able to detect malicious web pages as well as what type of malware they are trying to push. We download the malware for further analysis and add the malicious sites to a blacklist.

*Our Honeypots are constantly crawling the web so that we can detect infected web pages in real time, before the end user does.

Below is one machine hard at work, collecting honey ;-)

<img style="BORDER-RIGHT: black 1px solid; BORDER-TOP: black 1px solid; BORDER-LEFT: black 1px solid; BORDER-BOTTOM: black 1px solid" src="http://blogs.paretologic.com/malwarediaries/wp-content/uploads/2008/10/honey.png" alt="" width="638" height="536" />

Jerome
i would like to help out with this has i get infected with my pc's every year at least once or twice and im sick of it i got a laptop i use once in a while witch i can use for a honeypot just email me the answer at ********* that is my gaming mail address and i check it three times a day

Thanks Your Hating Malware Friend

Mike
Reply With Quote
  #3  
Old 10-15-2008, 02:07 AM
BradandPitti BradandPitti is offline
Junior Member
Join Date: Oct 2008
Posts: 1
Default Hello nice site

cool site
Reply With Quote
  #4  
Old 10-20-2008, 06:00 PM
May's Avatar
May May is offline
Super Moderator
Join Date: Oct 2007
Posts: 33
Default To DarkClow

Hello Mike,

To protect your privcy we do not post your email address here, but you will be contacted by our moderator by email separately. Cheers,
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use