Is anything truly secure...

9 Comments on “How Long is the Waledac Binary Update Cycle?”

  1. Edgar
    Very nice tracker about Binary Update Cycle. I have one little problem when i use repoort filter about Fast Flux IPs Harvested I tried to filter the data in the report Fast Flux IPs Harvested for LAST SEEN, but I get this error after the first page Example: flter for last seen -> 2009-02-05 result is: 67 found by search. Page 1 of 2 [Next] [Last Page] Page 1 show correct, if i choose page 2 i receive this error ---> Error, query failed Edgar
  2. Edgar
    I make a little comparison between the ip detected in interval 5 hours from the tracker and my AutoIt script The results seem to be very close http://edetools.blogspot.com/2009/02/botnet-waledac-alcune-verifiche.html Edgar :)
  3. jeremy
    Edgar, one thing I should make clear is that to optimize the database the IP->Domain relationship for my tracker is last associated Domain. What I mean is several of the Waledac IPs are shared between domain names, so if an IP is seen in a order of say X domain, Y domain, and Z domain the tracker will show that IP associated with Z domain and not X domain and Y domain. So comparing a single domain name walk with your whois tool to the results found in my Tracker is not 100% accurate.
  4. Edgar
    I understand and also some Waledac Domain names are more popular than others. Thinking of this I created a script that does not make a whois on a single domain but on a number of domains between the more 'popular and I want to see if the results change. I have a question for you: What do you think about Chinese and Korean domains that now are disappeared from the reports ? Becouse i think Korea and China have one big numbers of infected computers. Edgar
  5. jeremy
    Edgar, I am not sure what to think of this... It does appear as though the authors are experimenting with the segregation of their botnet though. If I have sometime in the next few days I may create some new view points into the data that will track these types of things. Maybe it will provide some interesting statistics or data views for us.
  6. Edgar
    For curiosity 'I made a script that uses various domain names waledac and not just only one in whois test. The result is' that whois show different domains always associated with groups of a same IP address http://edetools.blogspot.com/2009/02/botnet-waledac-alcune-verifiche-parte-2.html Edgar :)
  7. Edgar
    Now Waledac pages have iframe with link a other waledac domain with code and links a page software in russian - english language. more info at http://edetools.blogspot.com/2009/02/aggiornamento-waledac-11-febbraio_11.html Edgar :)

Comments are closed.

Copyright © 2013 SudoSecure LLC. All rights reserved.

rvn_polyon_theme rvn_polyon_theme_tv_1_7 rvn_polyon_theme_fwv_2_2