BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command &...

17

Transcript of BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command &...

Page 1: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication
Page 2: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

BEM-VINDOS

Page 3: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

WORKSHOP BOTNET

Page 4: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

AGENDA

• Introdução

• Bots e Botnets ?!

• Propósitos

• Cases

• Hands-on

Page 5: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

BOTS E BOTNETS ?!

• Bots são programas de computador ou scripts projetados para executar uma série de operações automaticamente.

• Botnets são uma rede de computadores infectados, ou bots, sob o controle de uma única parte, conhecida como “bot master".

Page 6: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

BOTNETS

• Bots (Zombies)

• Botmaster (Bot herder)

• Command and Control Server (C&C)

Page 7: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

BOTNETS

Page 8: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

PROPÓSITOS

• Comunicação

• Compartilhamento de informações (data leak)

• Curiosidade

• Fun

• $$$$$$

Page 9: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

MIRAI

Foi usada para derrubar grandes serviços como a PlayStation Network, Spotify, Twitter e PayPal. A Mirai controlava mais de 300 mil dispositivos, incluindo câmeras de segurança e roteadores, para direcionar tráfego em ataques DDoS.

Page 10: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

MIRAI

Page 11: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

CENÁRIO ATUAL

Page 12: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

CENÁRIO ATUAL

Page 13: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

LET`S GO

Page 14: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

HANDS-ON

• https://github.com/vinicius3cta/Ares

Page 15: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

HANDS-ON

• Servidor: Kali ou Ubuntu

• Cliente: Ubuntu

Page 16: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication

HANDS-ON

• VirtualBox

• Servidor: NAT / Host-Only

• Cliente: Hosty-Only

• apt update && apt upgrade

• git clone https://github.com/vinicius3cta/Ares.git

• pip install -r requirements.txt

Page 17: BEM-VINDOS · (Bot/Zombie) Cybercriminal (Botmaster) social media posts Botnet Connection Command & Control Server (c2) Control EMSISOFT Spam emails Infected websites Multiplication