massive botnet controlling some 1.9 million zombie comp

Jacee

Consumer Security
Guru
Gold Member
VIP
Local time
6:09 AM
Messages
8,608
Do you know what your computer is doing tonight? :shock:

Finjan Reveals 1.9 Million-Strong Botnet at RSA

The size of the network would make it possibly the largest botnet under the control of cyber-thieves. Some 45 percent of the IP addresses under the control of the network are located in the U.S., compared to six percent in the U.K., three percent in France and four percent in Canada and Germany. The geo-location of 38 percent of the IP addresses could not be determined.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Thanks for the news.
 

My Computer My Computer

At a glance

Vista Ult64, Win7600Intel Core 2 Quad Q6600 @ 2400 MHz 64bit OS4096 MB DDR3-SDRAMATI Radeon HD 3870 Series x2 Crossfired
Computer Manufacturer/Model Number
Self Build 64bit
OS
Vista Ult64, Win7600
CPU
Intel Core 2 Quad Q6600 @ 2400 MHz 64bit OS
Motherboard
Asus P5E3 Deluxe WiFi @p 64 bit OS
Memory
4096 MB DDR3-SDRAM
Graphics Card(s)
ATI Radeon HD 3870 Series x2 Crossfired
Sound Card
Realtek on board
Monitor(s) Displays
Samsung SyncMaster - 23 inches
Screen Resolution
1680x1050 pixels at 60 Hz in True Colors
Hard Drives
Hitachi (250 GB)/Samsung 750 GB. /Barracuda 160 GB.
My Book 1 TB external..
PSU
Cooler Master 1000w
Case
Cooler Master Cosmos 1000.
Cooling
Fans and fresh air,
Keyboard
Wireless
Mouse
Wireless
Internet Speed
Never fast enough
Other Info
I use a Magnum.
We are Borg; resistance is futile.
 

My Computer My Computer

At a glance

Win.7.Ult.x64Intel Core i7 97012GB (6x2GB) OCZ Platinum DDR3 1600Gigabyte GV-R485MC-1GH, ATI 4850, 1GB GDDR3, ...
Computer Manufacturer/Model Number
home brew
OS
Win.7.Ult.x64
CPU
Intel Core i7 970
Motherboard
Gigabyte GA-X58-UD5
Memory
12GB (6x2GB) OCZ Platinum DDR3 1600
Graphics Card(s)
Gigabyte GV-R485MC-1GH, ATI 4850, 1GB GDDR3, passive cooler
Sound Card
(on-board) Speakers - Klipsch ProMedia 2.1
Monitor(s) Displays
2x Dell U2410 (H-IPS)
Screen Resolution
1920x1200, 1920x1200
Hard Drives
System = Intel 320 160GB SSD --
Data = 2x WD2002FAEX, RAID1 (ICH10R) --
Backup = 5x WD20EARS (eSata port) --
Add'l Storage = 8x WD20EARS, RAID6 (Adaptec 5805)
PSU
PCP&C S75QB
Case
Lian Li PC-V2010B + EX-H34 expansion HD cage
Cooling
Xigmatek HDT-1283 heatsink & bracket + Scythe S-Flex SFF21E
Keyboard
Das Keyboard Professional, Logitech UltraX
Mouse
Logitech G400
Internet Speed
6.85 Mb/s down, 0.35 Mb/s up (typical)
Other Info
Pioneer DVR-217DBK burner --
stock Lian Li case fans + BS-06 PCI 140mm exhaust (all set on 'low')
Thanks Jacee, that's a huge number of infected machines. :shock:
 

My Computer My Computer

At a glance

Windows 7 Ultimate Vista Ultimate x64Core 2 Duo E8500 3.16Ghz @ 3.8Ghz2x2Gigs Patriot PC2-6400 LLInno3D GeForce GTX260 216 SP
Computer Manufacturer/Model Number
Home Brew
OS
Windows 7 Ultimate Vista Ultimate x64
CPU
Core 2 Duo E8500 3.16Ghz @ 3.8Ghz
Motherboard
eVGA 750i FTW
Memory
2x2Gigs Patriot PC2-6400 LL
Graphics Card(s)
Inno3D GeForce GTX260 216 SP
Monitor(s) Displays
ASUS VW222U 22" 2ms Response time
Screen Resolution
1680x1050
Hard Drives
SATA 150GB
SATA II 250GB
USB IDE 750GB Ext.
PSU
HYTEC 600W & Thermaltake 650W Toughpower Power Exp
Case
Thermaltake Armor LCS (Liquid Cooling System)
Cooling
Liquid Cooling System
Keyboard
Logitech G15 Gaming Keyboard
Mouse
Logitech G9 Gaming Mouse

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
That's all those folks installing 7106...

You know, I'm really only half joking. Seems there are quite a few folks posting 7106 torrents and trying to convince people they're unadulterated even in the face of stark proof of the opposite. Why? What's it to them if someone they don't know uses it or not? Why the vested interest? There's no point system that I know of. Or is there? Has anyone grabbed these builds and tested them for outbound IRC traffic?

Were the world working as it should, the researchers would deliver a list of infected MAC addresses to the listed domain contacts along with a list of affected ports. This filter list would be loaded into the border routers as a BGP update immediately for maximum protection to the rest of the Internet and email sent to the affected customers in case of ISP or InfoSec depts in the case of corporations. Filters could then be put in place as fast as possible to protect the domain internally. But at least it wouldn't leak crap outside the domain in the short term.

But instead of doing something like this to contain the issue, they write a paper and wait to attend a trade show and brag about how cool they are that they found this big botnet while it continues to exist and do whatever it is it wants unfettered. Makes no bloody sense to me -- obviously this security expert is out to make a buck and a name for himself and has no interest in protecting the Internet at all or they'd at least be TRYING to mitigate the risk and affect with the networking tools and skills at their disposal. I'd think I'd get a better name at the trade show for presenting how I discovered and SHUT DOWN the botnet. While prominently listing any domains that failed to co-operate. Hopefully you'd get a few government agencies and fortune 500s that you could spread all over the new and shame the rest into action.
 
Last edited:

My Computer My Computer

At a glance

El Capitan / Windows 10i7-4980HQ16GBIris 5200
Computer type
Laptop
Computer Manufacturer/Model Number
Apple
OS
El Capitan / Windows 10
CPU
i7-4980HQ
Memory
16GB
Graphics Card(s)
Iris 5200
We have quite an extensive list of IP#'s and Domains, but there is a problem with some webhosts ... they will take paymment over security. Some are really responsible about shutting these sites down... others rely on thier monthly income and don't give a whit (or whatever)

So, as your post goes baarod, all we can do is try to warn and protect peback's :p

That's why I posted this article.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I read the article to which Jacee's post linked. It stated that the authors had reported details of the botnet to appropriate security and law enforcement agencies. While they may well be out to make a name for themselves, my impression was that they had done the right thing.
 

My Computer My Computer

At a glance

Win.7.Ult.x64Intel Core i7 97012GB (6x2GB) OCZ Platinum DDR3 1600Gigabyte GV-R485MC-1GH, ATI 4850, 1GB GDDR3, ...
Computer Manufacturer/Model Number
home brew
OS
Win.7.Ult.x64
CPU
Intel Core i7 970
Motherboard
Gigabyte GA-X58-UD5
Memory
12GB (6x2GB) OCZ Platinum DDR3 1600
Graphics Card(s)
Gigabyte GV-R485MC-1GH, ATI 4850, 1GB GDDR3, passive cooler
Sound Card
(on-board) Speakers - Klipsch ProMedia 2.1
Monitor(s) Displays
2x Dell U2410 (H-IPS)
Screen Resolution
1920x1200, 1920x1200
Hard Drives
System = Intel 320 160GB SSD --
Data = 2x WD2002FAEX, RAID1 (ICH10R) --
Backup = 5x WD20EARS (eSata port) --
Add'l Storage = 8x WD20EARS, RAID6 (Adaptec 5805)
PSU
PCP&C S75QB
Case
Lian Li PC-V2010B + EX-H34 expansion HD cage
Cooling
Xigmatek HDT-1283 heatsink & bracket + Scythe S-Flex SFF21E
Keyboard
Das Keyboard Professional, Logitech UltraX
Mouse
Logitech G400
Internet Speed
6.85 Mb/s down, 0.35 Mb/s up (typical)
Other Info
Pioneer DVR-217DBK burner --
stock Lian Li case fans + BS-06 PCI 140mm exhaust (all set on 'low')
Security and law enforcement -- who exactly? I don't know of any outfit in the government that handles this. It's really up to Sprint, et. el. who operate the backbones and that's not quite how it ought to be. When a domain refuses to filter their traffic for the good of the net, then it ought to be done for them. There are border routers on both sides of a leased line. If the domain owner won't add the filtering then the carrier should be required by law to do so.

NEWSFLASH:

Looks like cybersecurity's going to be under direct presidential control!

http://www.crn.com/government/217100034;jsessionid=55VP02WADXRZUQSNDLPSKH0CJUNN2JVN
 
Last edited:

My Computer My Computer

At a glance

El Capitan / Windows 10i7-4980HQ16GBIris 5200
Computer type
Laptop
Computer Manufacturer/Model Number
Apple
OS
El Capitan / Windows 10
CPU
i7-4980HQ
Memory
16GB
Graphics Card(s)
Iris 5200
Back
Top