Fingerprinting Botnet C&C Servers
April 13, 2006 by Jose NazarioOne of the things we’re doing in our work, and that will likely appear in our VBCon 06 paper, is understanding the distribution of OS’ per botnet command and control (c&c) server. I’ve been using a few tools to do this (it is in bulk…thousands of botnet servers; scripting “nmap -O” is the last resort), [...]