Dridex network traffic analysis -- 3
Budget: £10 – £20 GBP
The task is to identify specific network features of the Dridex malware from provided pcap files and generate a small report on how the malware operates in a network sense. All findings must be related to its network behaviour, excluding anything to do with how the malware behaves on the system. Identify at least 5 distinctive features that are common in both PCAP files relating to the Dridex malware.
The report should contain findings and other key information from the internet, mainly answering the following questions:
How does it spread on the network (Ports/services)?
How does it reach it's c&c server or communicate with it?
The p2p communication mechanism and why each peer connects to the other?
How do infected bots get information about each other and how are they added to a botnet?
What communication algorithms are used in P2P communication or communication between node and c&c servers?
The PCAP files will be sent once the project has been accepted
The report should contain findings and other key information from the internet, mainly answering the following questions:
How does it spread on the network (Ports/services)?
How does it reach it's c&c server or communicate with it?
The p2p communication mechanism and why each peer connects to the other?
How do infected bots get information about each other and how are they added to a botnet?
What communication algorithms are used in P2P communication or communication between node and c&c servers?
The PCAP files will be sent once the project has been accepted
Related categories:
Web Security
Wireless
Computer Security
Network Administration
Internet Security