A forum for reverse engineering, OS internals and malware analysis 

 #25778  by dejl13
 Mon May 04, 2015 12:33 am
voroojax wrote:You should receive occasionally. If not, something is wrong. for example make sure your VM is not behind NAT!
I'm receiving connections now but no binaries, the VM is not behind a NAT at all. It has a public globally routable IP Address and no incoming or outgoing ports are blocked.
 #25786  by dejl13
 Mon May 04, 2015 6:32 am
voroojax wrote:if your config is correct, you'll receive eventually. but be warned, they are mostly kiddo variants!
Personally I prefer reading dionaea logs instead looking at binaries.
What do you mean by "kiddo variants"? n00b copypasta? ;p
 #25812  by dejl13
 Thu May 07, 2015 9:41 am
Vrtule wrote:A friend of mine runs several honeypots, including Dionea and most of the received binaries (97+ % IIRC) are Conflickers.
Sadly still no binaries yet, any suggestions where I can post the IP?