Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

US Army Research Office’s BotHunter ( Malware detector)
Antispyware ^ | Wednesday, November 26th, 2008 at 12:53 pm | staff

Posted on 12/08/2008 9:47:54 AM PST by Ernest_at_the_Beach

When malware spammers get out of control, what’s the best thing to do?

Call in the US Army, perhaps?

A free malware-detector called BotHunter, sponsored by the US Army Research Office, “works so well that it has even found infected Mac computers, much to the embarrassment of the Mac owners who, of course, swear that their computers cannot be infected with bots,” SC Magazine quotes Marcus Sachs, director at SANS Internet Storm Center, as saying.

And there have been 35,000 downloads so far, the story has Phillip Porras, program director of enterprise and infrastructure security at SRI International, a research and technology organization, and lead developer of the BotHunter project, saying.

“It works so well that it has even found infected Mac computers, much to the embarrassment of the Mac owners who, of course, swear that their computers cannot be infected with bots,” Marcus Sachs, director at SANS Internet Storm Center, told SCMagazineUS.com Tuesday in an email.

BotHunter was funded through a Cyber-Threat Analytics research grant from the US Army Research Office, says SC Magazine, adding:

“It reportedly helps Windows, Mac and Linux users detect malware-infected hosts on their networks by tracking interactions that typically occur when a PC is infected with malware, Porras said. The tool will generate an infection profile with all the forensic evidence that was gathered.

“The infection profile report will then allow users to determine which machines on the network are acting like they are infected. The tool anonymizes infection profiles and passes them back to SRI, where they go into a repository that is used to help generate new threat intelligence.”



TOPICS: Computers/Internet
KEYWORDS: bothunter; botnet; malware
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081 next last
To: IYAS9YAS

...I’m no help....someone may be along shortly to give suggestions...


21 posted on 12/08/2008 10:21:16 AM PST by Ernest_at_the_Beach (No Burkas for my Grandaughters!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Ernest_at_the_Beach

Thanks!!

I hadn’t heard of this either. I’ll check it out.


22 posted on 12/08/2008 10:25:29 AM PST by KoRn
[ Post Reply | Private Reply | To 6 | View Replies]

To: KoRn

Give us some feedback when you can!


23 posted on 12/08/2008 10:29:05 AM PST by Ernest_at_the_Beach (No Burkas for my Grandaughters!)
[ Post Reply | Private Reply | To 22 | View Replies]

Bookmark


24 posted on 12/08/2008 10:31:05 AM PST by Joiseydude (Let the Hero, born of woman, crush the serpent with his heel,)
[ Post Reply | Private Reply | To 22 | View Replies]

To: Ernest_at_the_Beach

Will do. I’ll be traveling for business over the next few weeks but I’ll post what/when I can.


25 posted on 12/08/2008 10:34:47 AM PST by Bloody Sam Roberts (Inspiration: The momentary cessation of stupidity.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: yankeedame; Snurple; Dr. Sivana; CarrotAndStick; Smogger; RightOnTheLeftCoast; bamahead; ...

Saw your posts on the Malware keyword list....looking for people that may have or might try this and give the community some feedback ...


26 posted on 12/08/2008 10:36:25 AM PST by Ernest_at_the_Beach (No Burkas for my Grandaughters!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
"Give us some feedback when you can!"

Will do. I'll get it running on a machine that's plugged into a span port on one of our more centralized switches. I'll also give it a try in our DMZ.

27 posted on 12/08/2008 10:42:20 AM PST by KoRn
[ Post Reply | Private Reply | To 23 | View Replies]

To: Ernest_at_the_Beach; All
Y'all realize the site this thread links to is a spyware site?

Just for grins, google Antispyware.com and then give yourself a swift kick...

“I have this antispyware.com comes up aout every five minutes how ... 7 posts - 6 authors - Last post: May 31, 2006
I have this antispyware.com comes up aout every five minutes how do I get rid of it?
answers.yahoo.com/question/index?qid=20060617223627AAFZCqp - 49k - Cached - Similar pages
Malware Advisor: Beware SpywareBot & antispyware.com!! Beware SpywareBot & antispyware.com!! Thanks to some info from the Sunbelt blog, this website, which was recently sold for $500000 has an app associated ...
temerc.blogspot.com/2006/12/beware-spywarebot-antispywarecom.html - 186k - Cached - Similar pages
Before You Buy That Anti-Spyware Program - Security Fix First of all, some of the best anti-spyware tools out there today are free. We review at least four of them in the video tutorials on computer security that ...
voices.washingtonpost.com/securityfix/2005/05/before_you_buy_that_”

28 posted on 12/08/2008 10:51:30 AM PST by Old Student (We have a name for the people who think indiscriminate killing is fine. They're called "The Bad Guys)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Old Student

Oh really....just damn!


29 posted on 12/08/2008 10:56:53 AM PST by Ernest_at_the_Beach (No Burkas for my Grandaughters!)
[ Post Reply | Private Reply | To 28 | View Replies]

To: Old Student

LOL!


30 posted on 12/08/2008 10:58:20 AM PST by SIDENET (Hubba Hubba...)
[ Post Reply | Private Reply | To 28 | View Replies]

To: Old Student
Well we need to sort this out....I have my grandaughter in at the moment to help with cleaning...so I need to break out for awhile!

Did find this.:

************************

Antispyware.com pop ups Major Geeks

31 posted on 12/08/2008 11:01:56 AM PST by Ernest_at_the_Beach (No Burkas for my Grandaughters!)
[ Post Reply | Private Reply | To 28 | View Replies]

To: Ernest_at_the_Beach
“Oh really....just damn!”

If it helps any, BotHunter is apparently real, but the reference I looked at said it is Linux only.

32 posted on 12/08/2008 11:02:46 AM PST by Old Student (We have a name for the people who think indiscriminate killing is fine. They're called "The Bad Guys)
[ Post Reply | Private Reply | To 29 | View Replies]

To: Old Student; SIDENET; ShadowAce; KoRn; Bloody Sam Roberts

Well,...I first saw the note at Distrowatchweekly and then went googling and found the article at Antispyware...I think the links to Bothunter are legit....


33 posted on 12/08/2008 11:05:33 AM PST by Ernest_at_the_Beach (No Burkas for my Grandaughters!)
[ Post Reply | Private Reply | To 28 | View Replies]

To: Old Student
I do know for a fact antispyware.com is a spyware site, had to clean it off my wife's computer several weeks ago. PITA, I tell you! Google “remove antispyware.com”, and I think that will get you to several sites that detail the process.

I am using McAfee AV these days, on my father-in-law's recommendation. He's an engineer and programmer, and although I don't much like him, I respect h### out of his recommendations, and McAfee warns you of troublesome websites. Like this one.

34 posted on 12/08/2008 11:06:49 AM PST by Old Student (We have a name for the people who think indiscriminate killing is fine. They're called "The Bad Guys)
[ Post Reply | Private Reply | To 32 | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

35 posted on 12/08/2008 11:09:35 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SIDENET

“LOL!”

As they say, “Life is a beach, and then you get sand in your shorts...”

;)


36 posted on 12/08/2008 11:10:56 AM PST by Old Student (We have a name for the people who think indiscriminate killing is fine. They're called "The Bad Guys)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Old Student

I think I saw a reference to a Windows version....


37 posted on 12/08/2008 11:15:00 AM PST by Ernest_at_the_Beach (No Burkas for my Grandaughters!)
[ Post Reply | Private Reply | To 32 | View Replies]

To: Ernest_at_the_Beach

Re: bots on Macs

I am very skeptical about the claims of finding ‘bots on Macs. If this were true we would have heard of it before. Developing a major app like this with so many cross platform and cross processor ( both Intel AND PowerPC?) for simutaneous release is not an easy task. I cannot believe that these Mac spambots have somehow been overlooked by Secunia, Symantec, et al. It sounds like FUD to me.

I’m on my iPhone right now but I’ll ping the Mac list when I get home later today.


38 posted on 12/08/2008 11:24:32 AM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
# * Windows XP Distribution v1.0.2 (Official Release) - 14 November 2008 # BotHunter-Win32-v1.0.2.exe, (MD5 = 30aa9d81bab1709be2b61e428461666b) # INSTALLATION ADVICE FOR WINDOWS USERS: Click Here # Download from Mirror Sites: [SRI], [EmergingThreats], [DShield] # Windows XP: this self-installing Win32 executable will install all necessary supporting packagesErnest_at_the_Beach - What about Vista? Can I download the XP software?
39 posted on 12/08/2008 11:37:47 AM PST by GOPJ (Perverse incentives birth nasty unintended consequences.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Ernest_at_the_Beach
# * Windows XP Distribution v1.0.2 (Official Release) - 14 November 2008 # BotHunter-Win32-v1.0.2.exe, (MD5 = 30aa9d81bab1709be2b61e428461666b) # INSTALLATION ADVICE FOR WINDOWS USERS: Click Here # Download from Mirror Sites: [SRI], [EmergingThreats], [DShield] # Windows XP: this self-installing Win32 executable will install all necessary supporting packages

Ernest_at_the_Beach - What about Vista? Can I download the XP software?

40 posted on 12/08/2008 11:38:10 AM PST by GOPJ (Perverse incentives birth nasty unintended consequences.)
[ Post Reply | Private Reply | To 3 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson