| Windows 7: massive botnet controlling some 1.9 million zombie comp |
22 Apr 2009
|
#1 | | Windows 7 Ultimate 32bit SP1 |
massive botnet controlling some 1.9 million zombie comp Do you know what your computer is doing tonight? Finjan Reveals 1.9 Million-Strong Botnet at RSA Quote: The size of the network would make it possibly the largest botnet under the control of cyber-thieves. Some 45 percent of the IP addresses under the control of the network are located in the U.S., compared to six percent in the U.K., three percent in France and four percent in Canada and Germany. The geo-location of 38 percent of the IP addresses could not be determined. | My System Specs |
| System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
22 Apr 2009
|
#2 | | Vista Ult64, Win7600 Dublin |
| My System Specs | | System Manufacturer/Model Number Self Build 64bit OS Vista Ult64, Win7600 CPU Intel Core 2 Quad Q6600 @ 2400 MHz 64bit OS Motherboard Asus P5E3 Deluxe WiFi @p 64 bit OS Memory 4096 MB DDR3-SDRAM Graphics Card ATI Radeon HD 3870 Series x2 Crossfired Sound Card Realtek on board Monitor(s) Displays Samsung SyncMaster - 23 inches Screen Resolution 1680x1050 pixels at 60 Hz in True Colors Keyboard Wireless Mouse Wireless PSU Cooler Master 1000w Case Cooler Master Cosmos 1000. Cooling Fans and fresh air, Hard Drives Hitachi (250 GB)/Samsung 750 GB. /Barracuda 160 GB.
My Book 1 TB external.. Internet Speed Never fast enough Other Info I use a Magnum. |
22 Apr 2009
|
#3 | | |
We are Borg; resistance is futile. | My System Specs | | System Manufacturer/Model Number home brew OS Win.7.Ult.x64 CPU Intel Core i7 970 Motherboard Gigabyte GA-X58-UD5 Memory 12GB (6x2GB) OCZ Platinum DDR3 1600 Graphics Card Gigabyte GV-R485MC-1GH, ATI 4850, 1GB GDDR3, passive cooler Sound Card (on-board) Speakers - Klipsch ProMedia 2.1 Monitor(s) Displays 2x Dell U2410 (H-IPS) Screen Resolution 1920x1200, 1920x1200 Keyboard Das Keyboard Professional, Logitech UltraX Mouse Logitech G400 PSU PCP&C S75QB Case Lian Li PC-V2010B + EX-H34 expansion HD cage Cooling Xigmatek HDT-1283 heatsink & bracket + Scythe S-Flex SFF21E Hard Drives System = Intel 320 160GB SSD --
Data = 2x WD2002FAEX, RAID1 (ICH10R) --
Backup = 5x WD20EARS (eSata port) --
Add'l Storage = 8x WD20EARS, RAID6 (Adaptec 5805) Internet Speed 6.85 Mb/s down, 0.35 Mb/s up (typical) Other Info Pioneer DVR-217DBK burner --
stock Lian Li case fans + BS-06 PCI 140mm exhaust (all set on 'low') |
22 Apr 2009
|
#4 | | Windows 7 Ultimate Vista Ultimate x64 QLD, Cairns |
Thanks Jacee, that's a huge number of infected machines. | My System Specs | | System Manufacturer/Model Number Home Brew OS Windows 7 Ultimate Vista Ultimate x64 CPU Core 2 Duo E8500 3.16Ghz @ 3.8Ghz Motherboard eVGA 750i FTW Memory 2x2Gigs Patriot PC2-6400 LL Graphics Card Inno3D GeForce GTX260 216 SP Monitor(s) Displays ASUS VW222U 22" 2ms Response time Screen Resolution 1680x1050 Keyboard Logitech G15 Gaming Keyboard Mouse Logitech G9 Gaming Mouse PSU HYTEC 600W & Thermaltake 650W Toughpower Power Exp Case Thermaltake Armor LCS (Liquid Cooling System) Cooling Liquid Cooling System Hard Drives SATA 150GB
SATA II 250GB
USB IDE 750GB Ext. |
22 Apr 2009
|
#5 | | Windows 7 Ultimate 32bit SP1 |
Quote: We are Borg; resistance is futile ermmm? | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
22 Apr 2009
|
#6 | | Windows 7 Ultimate 64-bit Chicago |
That's all those folks installing 7106...
You know, I'm really only half joking. Seems there are quite a few folks posting 7106 torrents and trying to convince people they're unadulterated even in the face of stark proof of the opposite. Why? What's it to them if someone they don't know uses it or not? Why the vested interest? There's no point system that I know of. Or is there? Has anyone grabbed these builds and tested them for outbound IRC traffic?
Were the world working as it should, the researchers would deliver a list of infected MAC addresses to the listed domain contacts along with a list of affected ports. This filter list would be loaded into the border routers as a BGP update immediately for maximum protection to the rest of the Internet and email sent to the affected customers in case of ISP or InfoSec depts in the case of corporations. Filters could then be put in place as fast as possible to protect the domain internally. But at least it wouldn't leak crap outside the domain in the short term.
But instead of doing something like this to contain the issue, they write a paper and wait to attend a trade show and brag about how cool they are that they found this big botnet while it continues to exist and do whatever it is it wants unfettered. Makes no bloody sense to me -- obviously this security expert is out to make a buck and a name for himself and has no interest in protecting the Internet at all or they'd at least be TRYING to mitigate the risk and affect with the networking tools and skills at their disposal. I'd think I'd get a better name at the trade show for presenting how I discovered and SHUT DOWN the botnet. While prominently listing any domains that failed to co-operate. Hopefully you'd get a few government agencies and fortune 500s that you could spread all over the new and shame the rest into action.
Last edited by baarod; 22 Apr 2009 at 09:16 PM..
| My System Specs | | System Manufacturer/Model Number baarod/MCP OS Windows 7 Ultimate 64-bit CPU Core2 Quad Q6600 @ 3.6GHz 9x400FSB Motherboard Gigabyte G33M-S2H Memory 4GB DDR2 1066 Graphics Card ATI Radeon HD 4670 Sound Card Integrated Azalia Monitor(s) Displays Acer AL1711 Screen Resolution 1280x1024 Keyboard Microsoft Wireless Comfort Keyboard 4000 Mouse Microsoft Wireless Lasr Mouse 5000 PSU 240W TFX Case InWin BT566 Cooling Intel Retail Stock Hard Drives OCZ Vertex SATAII w/ 1.5FW 30,528MB system and apps
Maxtor 6L300R0 PATA 286,188MB page file, data and user profiles Internet Speed 3Mbps Verizon DSL over 802.11g Other Info Hauppauge WinTV PVR II Tuner, Generic $13 SoC Webcam, RT61 WiFi with remote antenna, Media Center Remote and Receiver |
22 Apr 2009
|
#7 | | Windows 7 Ultimate 32bit SP1 |
We have quite an extensive list of IP#'s and Domains, but there is a problem with some webhosts ... they will take paymment over security. Some are really responsible about shutting these sites down... others rely on thier monthly income and don't give a whit (or whatever)
So, as your post goes baarod, all we can do is try to warn and protect peback's
That's why I posted this article. | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
22 Apr 2009
|
#8 | | |
I read the article to which Jacee's post linked. It stated that the authors had reported details of the botnet to appropriate security and law enforcement agencies. While they may well be out to make a name for themselves, my impression was that they had done the right thing. | My System Specs | | System Manufacturer/Model Number home brew OS Win.7.Ult.x64 CPU Intel Core i7 970 Motherboard Gigabyte GA-X58-UD5 Memory 12GB (6x2GB) OCZ Platinum DDR3 1600 Graphics Card Gigabyte GV-R485MC-1GH, ATI 4850, 1GB GDDR3, passive cooler Sound Card (on-board) Speakers - Klipsch ProMedia 2.1 Monitor(s) Displays 2x Dell U2410 (H-IPS) Screen Resolution 1920x1200, 1920x1200 Keyboard Das Keyboard Professional, Logitech UltraX Mouse Logitech G400 PSU PCP&C S75QB Case Lian Li PC-V2010B + EX-H34 expansion HD cage Cooling Xigmatek HDT-1283 heatsink & bracket + Scythe S-Flex SFF21E Hard Drives System = Intel 320 160GB SSD --
Data = 2x WD2002FAEX, RAID1 (ICH10R) --
Backup = 5x WD20EARS (eSata port) --
Add'l Storage = 8x WD20EARS, RAID6 (Adaptec 5805) Internet Speed 6.85 Mb/s down, 0.35 Mb/s up (typical) Other Info Pioneer DVR-217DBK burner --
stock Lian Li case fans + BS-06 PCI 140mm exhaust (all set on 'low') |
22 Apr 2009
|
#9 | | Windows 7 Ultimate 64-bit Chicago |
Security and law enforcement -- who exactly? I don't know of any outfit in the government that handles this. It's really up to Sprint, et. el. who operate the backbones and that's not quite how it ought to be. When a domain refuses to filter their traffic for the good of the net, then it ought to be done for them. There are border routers on both sides of a leased line. If the domain owner won't add the filtering then the carrier should be required by law to do so.
NEWSFLASH:
Looks like cybersecurity's going to be under direct presidential control! http://www.crn.com/government/217100...PSKH0CJUNN2JVN
Last edited by baarod; 23 Apr 2009 at 01:22 PM..
| My System Specs | | System Manufacturer/Model Number baarod/MCP OS Windows 7 Ultimate 64-bit CPU Core2 Quad Q6600 @ 3.6GHz 9x400FSB Motherboard Gigabyte G33M-S2H Memory 4GB DDR2 1066 Graphics Card ATI Radeon HD 4670 Sound Card Integrated Azalia Monitor(s) Displays Acer AL1711 Screen Resolution 1280x1024 Keyboard Microsoft Wireless Comfort Keyboard 4000 Mouse Microsoft Wireless Lasr Mouse 5000 PSU 240W TFX Case InWin BT566 Cooling Intel Retail Stock Hard Drives OCZ Vertex SATAII w/ 1.5FW 30,528MB system and apps
Maxtor 6L300R0 PATA 286,188MB page file, data and user profiles Internet Speed 3Mbps Verizon DSL over 802.11g Other Info Hauppauge WinTV PVR II Tuner, Generic $13 SoC Webcam, RT61 WiFi with remote antenna, Media Center Remote and Receiver massive botnet controlling some 1.9 million zombie comp problems? All times are GMT -5. The time now is 11:57 PM. | |