ºÝºÝߣ

ºÝºÝߣShare a Scribd company logo
HONEYPOT SPOTTED
@Sh1n0g1
ABOUT ME
? @Sh1n0g1
? Security Researcher of Macnica Networks Corp.
? Malware Simulator Developer
Malware Simulators
? Backdoor Simulator
¨C ShinoBOT
¨C ShinoBOT.ps1
? APT Simulator
¨C ShinoBOT Suite
? Ransomware Simulator
¨C ShinoLocker
? ICS Malware Simulator
¨C ShinoICS (not published yet)
https://shinosec.com
QUESTION?
? How do the honeypots, malware
analysis systems, sandboxes look like
from the attacker's point of view?
Honeypot Spotted
Honeypot Spotted
Honeypot Spotted
Honeypot Spotted
Honeypot Spotted
BIG DATA ANALYTICS(hostname vs ip)
(n=5000)
Small Cluster
CLUSTER1
(n=5000)
Honeypot Spotted
Honeypot Spotted
CLUSTER2
(n=5000)
Honeypot Spotted
CLUSTER3
(n=5000)
Honeypot Spotted
Honeypot Spotted
"TO BE SPOTTED" does matter?
? Yes
? The attacker will create next malware which avoids
to be run on the honeypots/malware analytics
system/sandboxes
CONCLUSION
? Make your Honey pot "human-y" ¨P dirty
? Make your Honey pot "random"
? Use an IP address which does not related with you
¨C Cloud service should be good
THANK YOU
@Sh1n0g1
https://shinosec.com

More Related Content

Honeypot Spotted