This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

ZeroAccess Botnet

0

Looking for a filter in wireshark to help locate which computer is associated with the zeroaccess botnet. Or a filter to sort out bots on a network. Common things i should be looking for. Thanks

asked 01 Feb '16, 13:22

ghost90's gravatar image

ghost90
6112
accept rate: 0%

As not everyone here is familiar with zeroaccess botnet characteristic behaviour, can you describe it in free form? The task would then be simplified to translating it into a display filter syntax.

(01 Feb '16, 14:08) sindy