Wireshark Logs From Conficker
We captured some logs from Conficker which illustrate what it does.
The first screen shows the Conficker C variant and its well documented update mechanism through DNS queries.
Second screens shows some interesting P2P traffic, using the TCP protocol and the Kazaa network.
The IP sending those packets is located in China, registered under the “CNC Group Chongqing Province Network”.
The latest Conficker variant shows how well the Conficker infected nodes can communicate.
Jerome
No related posts.
Related posts brought to you by Yet Another Related Posts Plugin.


Leave a Reply