Dennis Schwarz's Posts

The Revolution Will Be Written in Delphi

May 21, 2013 by Dennis Schwarz

Since it has been a little while since we profiled a DDoS botnet family on the blog, let’s take a look at Trojan.BlackRev (also known as the “Black Revolution” trojan.) It was named for the Mutex set in early versions of the malware. This family is interesting from a research perspective because there are at [...]

Share
Read More

Digging Through an “Administrative Network Stressor” Provider’s Database

March 20, 2013 by Dennis Schwarz

On March 15, 2013, Brian Krebs of Krebs on Security wrote “The World Has No Room For Cowards.” In it, he writes a fascinating story about a DDoS attack against his site and also a physical attack against his person. The part where Krebs’ notes that “… there are strong indications that a site named [...]

Share
Read More

Scavenging Connections On Dynamic-IP Networks Redux

February 4, 2013 by Dennis Schwarz

While a lot has changed since Seth McGann’s 1998 Phrack magazine article “Scavenging Connections On Dynamic-IP Networks,” it’s not hard to extrapolate his idea into modern day malware sinkholes. In this blog post we would like to share some of the connections scavenged over a short period from the No-IP dynamic DNS network–a network we [...]

Share
Read More