+ All Categories
Home > Documents > If we control theseIP address of SMTP client. 6-character string compatible with Exim's message...

If we control theseIP address of SMTP client. 6-character string compatible with Exim's message...

Date post: 07-Aug-2020
Category:
Upload: others
View: 0 times
Download: 0 times
Share this document with a friend

Click here to load reader

Transcript
  • If we control these …

    … we can monitor & influence these

  • Types of Storm C&C Messages

    •  Activation (report from bot to botmaster) •  Email address harvests •  Spamming instructions •  Delivery reports •  DDoS instructions •  FastFlux instructions •  HTTP proxy instructions •  Sniffed passwords report •  IFRAME injection/report

  • Spam campaign mechanics

    TCP

    HTTP

    HTTP proxies

    Workers

    Proxy bots

    Botmaster

  • Campaign mechanics: harvest

    TCP

    HTTP

    HTTP proxies

    Workers

    Proxy bots

    Botmaster

    @ @ @ @

    @

    @ @ @

  • Campaign mechanics: spamming

    TCP

    HTTP

    HTTP proxies

    Workers

    Proxy bots

    Botmaster

  • Campaign mechanics: spamming

    TCP

    HTTP

    HTTP proxies

    Workers

    Proxy bots

    Botmaster

  • Campaign mechanics: reporting

    TCP

    HTTP

    HTTP proxies

    Workers

    Proxy bots

    Botmaster


Recommended