Re: Detecting Zombies?



John Oliver wrote:
On Thu, 04 Sep 2008 18:59:08 GMT, 7 wrote:
Inside a dos box, enter netstat -a to list all the connections.
If should be about ten lines if idling.

You cannot trust anything a potentially-compromised host will tell you.
Utilities like netstat will probably be replaced with copies that will
not display the malicious traffic.


You're giving the malware authors (or their potential "users") too much credit. Malware will often use basic hiding mechanisms, such as hiding its files in explorer or the process from task manager, but there is little point doing anything more sophisticated on a windows machine. It would be a great deal of work making a windows version of netstat that didn't show your malware (on open source OS's it's easy - download the source, add a couple of lines of filter, re-compile), and virtually no victim is going to think of using it. Any admin will normally use something like Spybot Search and Destroy, or some other popular malware finder - not netstat.
.



Relevant Pages

  • Re: Fedora 10 Preview: samba problem
    ... netstat -t -n shows over 930 ... The issue seems to start when the windows machine comes online. ... connections trying to connect to the ipp port. ...
    (Fedora)
  • Re: Fedora 10 Preview: samba problem
    ... to take a long time for the printer (Brother HL5050) to show up even on ... the local box using smbclient. ... netstat -t -n shows over 930 ... whenever a windows machine is online. ...
    (Fedora)