Friday, January 10, 2014

Botnet1 and filesplitter

So I have a few botnets running on some test machines and I record, and occasionally go over, their traffic. I noticed this morning one of them was sent a larger than normal file. I pulled the file and noticed it was an exe. This was a little out of the ordinary for this one since the botnet has already established itself on my pc and has been running a while

A quick strings of the file shows something about a program called filesplitter. It appears that software is used for splitting and combining large files. Interesting. I see a few possibilities with this. It may do something similar to Cryptolocker where it will manipulate local files for some reason. Or it could possibly be used to send out personal files to a remote server or even download pieces of files and reassemble them locally. The exe was crashing when I tried to run it directly though. We'll see what happens I guess.


No comments:

Post a Comment