Quote:
|
Originally Posted by OlRoy
I'm monitoring the traffic in Ethereal which confirms that I'm not getting much attack traffic. If I can't get malware from nepenthes, is there any other way to get it? I really want to do some behavior analysis.
|
That sounds kinda odd, I mean that I just made wc -l to my 24h log file and it had over 6k lines (spam, viruses etc .. ) and my Nepenthes listens just one (home)ip.
nepenthes.log (24h) 6,6k lines and without spam 4,3k
logged_downloads.log (24h) 300 lines
logged_submissions.log (24h) 131 lines
Maybe your ISP is doing good work against viruses.
Do you just need different malware for tests?
There is public malware libraries where you can dl lots of different virii if you need some, but I suspect that you want live virus traffic and I cant help with that.
////