Zeus Malware Analysis- Sophos UTM, Security Onion

I’ve posted about dynamic and automated analysis of the Zeus malware, but what about identifying Zeus from firewall & IDS logs? After executing Zeus, my Sophos UTM generated a few alerts. This is something that would absolutely stick out to me during daily log analysis. Drilling into the alert tells us threat “C2/Zaccess-A” attempted to … Continue reading "Zeus Malware Analysis- Sophos UTM, Security Onion"

Read More

Zeus Malware Analysis- Any.Run

I decided to run the Zeus Malware through an automated analysis tool and compare to what I saw using dynamic analysis with Remnux.  I’m using the malware analysis tool at app.any.run The free version only supports Windows 7 executables, which Zeus targets. After uploading the file, app.any.run displays a windows UI and what the malware … Continue reading "Zeus Malware Analysis- Any.Run"

Read More