Like anything these days, you have to disinfect it first. [Research Saturday]

Published: Aug. 8, 2020, 5 a.m.

b"\\u201cCyberbunker\\u201d refers to a criminal group that operated a \\u201cbulletproof\\u201d hosting facility out of an actual military bunker. \\u201cBullet Proof\\u201d hosting usually refers to hosting locations in countries with little or corrupt law enforcement, making shutting down criminal activity difficult. Cyberbunker, which is also known as \\u201cZYZtm\\u201d and \\u201cCalibour\\u201d, was a bit different in that it actually operated out of a bulletproof bunker. In September of last year, German police raided this actual Cyberbunker and arrested several suspects.\\nWhile most of the group's assets were seized during the initial raid, the IP address space remained and was later sold to Legaco Networks. Before being shut down, Legaco Networks temporarily redirected the traffic to the SANS Internet Storm Center honeypots for examination.\\nJoining us on this week's Research Saturday from SANS Technology Institute is graduate student Karim Lalji and Dean of Research Johannes Ullrich to discuss their experiences.\\xa0\\nThe research and blog post can be found here:\\xa0\\n Real-Time Honeypot Forensic Investigation on a German Organized Crime Network\\n Cyberbunker 2.0: Analysis of the Remnants of a Bullet Proof Hosting Provider"