<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"
	xml:lang="en-us">
	<title>Comments on Smashing the Mega-d/Ozdok botnet in 24 hours</title>
	<subtitle></subtitle>
	<link rel="self" type="application/atom+xml" title="Comments on Smashing the Mega-d/Ozdok botnet in 24 hours" href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok/comments/atom.xml" />
	<link rel="alternate" type="text/html" title="Smashing the Mega-d/Ozdok botnet in 24 hours" href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html"/>
	<generator uri="http://www.typepad.com/">TypePad</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<updated>2009-11-04T22:56:00Z</updated>
	<author>
		<name>FireEye, Inc.</name>
		<uri>http://blog.fireeye.com/research/</uri>
	</author>
	<id>tag:typepad.com,2003:http://blog.fireeye.com/research/2009/11/smashing-the-ozdok/comments/atom.xml/</id>
    
		<entry>
			<title>Robert commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="This is excellent work. Spam received by our Barracuda firewall has reduced from over 80K per day (95% of all..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef012876455567970c#comment-6a00d835018afd53ef012876455567970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef012876455567970c</id>
			<published>2009-12-11T10:04:48Z</published>
			<updated>2009-12-11T10:04:48Z</updated>
			<author>
				<name>Robert</name>
                
			</author>
			<summary>This is excellent work. Spam received by our Barracuda firewall has reduced from over 80K per day (95% of all...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;This is excellent work.  Spam received by our Barracuda firewall has reduced from over 80K per day (95% of all email received) to under 45K (91% of email).  If only some kind of organised international alliance could be formed to systematically work on this issue of botnets.  Decimating botnets consistently could eventually make illegal control of PCs and phishing spam campaigns unprofitable.  This could bring PCs to the same low level of security risk as Apple Macs.  Of course, other measures will also be required such as efficiently apprehending malware authors from all jurisdictions (whether based in Nigeria, Ukraine or US).&lt;/p&gt;

&lt;p&gt;I&amp;#39;m concerned that the larger firms (Microsoft, Symantec) may have a conflict of interest and might be less aggressive than they could be towards botnets so that they can sell security solutions (and &amp;quot;Genuine Windows&amp;quot;) to their customers.  I sincerely hope this isn&amp;#39;t the case.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>The Big Bad Wolf commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Wow, this is one hell of a PR stunt. Iwe never herd of u guys until now so it&#39;s one..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef012875bc597e970c#comment-6a00d835018afd53ef012875bc597e970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef012875bc597e970c</id>
			<published>2009-11-20T11:23:05Z</published>
			<updated>2010-06-11T04:42:42Z</updated>
			<author>
				<name>The Big Bad Wolf</name>
                <uri>http://profile.typepad.com/thebig</uri>
			</author>
			<summary>Wow, this is one hell of a PR stunt. Iwe never herd of u guys until now so it&#39;s one...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Wow, this is one hell of a PR stunt.&lt;br /&gt;
Iwe never herd of u guys until now so it&amp;#39;s one hell of a way to put the company on the map.&lt;/p&gt;

&lt;p&gt;Btw i usaly get around 20 spam mail a day and the last cupple of days iwe only gotten around 2-6 spam mails :)&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Sajid commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Interesting... Great effort, and nice job." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a6a0dc12970b#comment-6a00d835018afd53ef0120a6a0dc12970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a6a0dc12970b</id>
			<published>2009-11-15T08:14:33Z</published>
			<updated>2009-11-15T08:14:33Z</updated>
			<author>
				<name>Sajid</name>
                
			</author>
			<summary>Interesting... Great effort, and nice job.</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Interesting... Great effort, and nice job.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Atif Mushtaq commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Q2: How was my experience while interacting with ISPs/Hosting providers. Overall it was a great experience. 1. There were some..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a679ce3d970b#comment-6a00d835018afd53ef0120a679ce3d970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a679ce3d970b</id>
			<published>2009-11-11T19:53:46Z</published>
			<updated>2009-11-11T19:53:46Z</updated>
			<author>
				<name>Atif Mushtaq</name>
                <uri>http://blog.fireeye.com</uri>
			</author>
			<summary>Q2: How was my experience while interacting with ISPs/Hosting providers. Overall it was a great experience. 1. There were some...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Q2: How was my experience while interacting with ISPs/Hosting providers.&lt;/p&gt;

&lt;p&gt;Overall it was a great experience. &lt;/p&gt;

&lt;p&gt;1. There were some ISPs who never replied to our abuse notifications but pulled the plug silently.&lt;/p&gt;

&lt;p&gt;2. There were some ISPs who promptly replied to our abuse notifications and asked for more evidence. After seeing the evidence they pulled the plug and replied with a Thanks.&lt;/p&gt;

&lt;p&gt;3. There were some ISPs who did not respond to our notifications at all (mostly non US ). Result is that those servers are still up. Luckily it looks that bot herders simply abandoned those servers, as I am no more seeing any response coming out of these servers.&lt;/p&gt;

&lt;p&gt;One thing which was common in all the replies, was something like this:&lt;/p&gt;

&lt;p&gt;&amp;quot;We have notified our client about this problem and it looks that these servers were compromised and are now being re-imaged by the our clients&amp;quot;. &lt;/p&gt;

&lt;p&gt;It looks that ISPs are not convinced that these server might actually be owned by the bot herders. So It doesn&amp;#39;t matter what I personally think of this &amp;#39;owned vs compromised&amp;#39; theory, it is what we have to believe in too..&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Atif Mushtaq commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="There are many questions which are being asked by our readers, I would like this opportunity to answer most of..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a679b345970b#comment-6a00d835018afd53ef0120a679b345970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a679b345970b</id>
			<published>2009-11-11T19:24:18Z</published>
			<updated>2009-11-11T19:24:18Z</updated>
			<author>
				<name>Atif Mushtaq</name>
                <uri>http://blog.fireeye.com</uri>
			</author>
			<summary>There are many questions which are being asked by our readers, I would like this opportunity to answer most of...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;There are many questions which are being asked by our readers, I would like this opportunity to answer most of these frequently asked questions one by one.&lt;/p&gt;

&lt;p&gt;Q1: Killing the zombies machines or killing the malware itself by sending a specially crafted packet. &lt;/p&gt;

&lt;p&gt;There are two main points to be noted here..&lt;/p&gt;

&lt;p&gt;1.Is there any self destruction mechanism hidden in the code to force Ozdok for killing itself?  So far we are unable to find any such mechanism.  Our investigation for the Ozdok as a malware is still going on. I&amp;#39;ll let you guys know in case we come across any such mechanism.&lt;/p&gt;

&lt;p&gt;2. Even if there is any such mechanism, it will be completely illegal  to do so, US and international laws do not permit any such activity even if the intention behind is good.  So there is no chance that FireEye will involve itself in any such activity now and in future. It is sad but it is how it goes....&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>paul b commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="It&#39;s looking as if bounceback is starting to happen - is this because you can&#39;t afford to keep buying domains..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a67937dc970b#comment-6a00d835018afd53ef0120a67937dc970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a67937dc970b</id>
			<published>2009-11-11T17:00:32Z</published>
			<updated>2009-11-11T17:00:32Z</updated>
			<author>
				<name>paul b</name>
                
			</author>
			<summary>It&#39;s looking as if bounceback is starting to happen - is this because you can&#39;t afford to keep buying domains...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;It&amp;#39;s looking as if bounceback is starting to happen - is this because you can&amp;#39;t afford to keep buying domains in front of yourself, or are the herders routing around the damage?  &lt;/p&gt;

&lt;p&gt;At our location on Nov 7-8 we saw about 50% less spam than normal for a weekend, which is pretty remarkable.  The trend is reversing, with the 9th running around 60% of normal and the 10th ~80% of normal spam volume (all &amp;quot;days&amp;quot; are PST, not GMT, sorry.)&lt;/p&gt;

&lt;p&gt;Great work on showing what can be done with coordination and an understanding of command and control channels, though!  &lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Patrick M commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="You guys are making the Internet a better place for everyone, I wish more companies would do this sort of..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0128757b14b2970c#comment-6a00d835018afd53ef0128757b14b2970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0128757b14b2970c</id>
			<published>2009-11-11T16:46:46Z</published>
			<updated>2009-11-11T16:46:46Z</updated>
			<author>
				<name>Patrick M</name>
                
			</author>
			<summary>You guys are making the Internet a better place for everyone, I wish more companies would do this sort of...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;You guys are making the Internet a better place for everyone, I wish more companies would do this sort of thing. As an email server and network administrator, I thank you from the bottom of my heart.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>J commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Inspiring work! Its terrifying how big these things get." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0128757a0e10970c#comment-6a00d835018afd53ef0128757a0e10970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0128757a0e10970c</id>
			<published>2009-11-11T10:39:16Z</published>
			<updated>2009-11-11T10:39:16Z</updated>
			<author>
				<name>J</name>
                
			</author>
			<summary>Inspiring work! Its terrifying how big these things get.</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Inspiring work!  Its terrifying how big these things get.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Ross Thomas commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Fantastic! Another one bites the dust. Good work, guys :)" href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a6763ec2970b#comment-6a00d835018afd53ef0120a6763ec2970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a6763ec2970b</id>
			<published>2009-11-11T00:35:54Z</published>
			<updated>2009-11-11T00:35:54Z</updated>
			<author>
				<name>Ross Thomas</name>
                
			</author>
			<summary>Fantastic! Another one bites the dust. Good work, guys :)</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Fantastic! Another one bites the dust. Good work, guys :)&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>anon commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Have you considered trying to establish your own c&amp;c facility to instruct infected machines to clean themselves?" href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a671a9c2970b#comment-6a00d835018afd53ef0120a671a9c2970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a671a9c2970b</id>
			<published>2009-11-10T21:25:11Z</published>
			<updated>2009-11-10T21:25:11Z</updated>
			<author>
				<name>anon</name>
                
			</author>
			<summary>Have you considered trying to establish your own c&amp;c facility to instruct infected machines to clean themselves?</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Have you considered trying to establish your own c&amp;amp;c facility to instruct infected machines to clean themselves?  &lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Meh commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="So... you worked for free and now have nothing more to talk about? Oh! I know, you can tell us..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a66ecdb2970b#comment-6a00d835018afd53ef0120a66ecdb2970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a66ecdb2970b</id>
			<published>2009-11-10T16:51:58Z</published>
			<updated>2009-11-10T16:51:58Z</updated>
			<author>
				<name>Meh</name>
                
			</author>
			<summary>So... you worked for free and now have nothing more to talk about? Oh! I know, you can tell us...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;So... you worked for free and now have nothing more to talk about? Oh! I know, you can tell us how your email campaign with isps works out for you.&lt;/p&gt;

&lt;p&gt;It&amp;#39;s generally a good idea not to do things that put yourself out of business. Well maybe you can have a good cry over a beer with these spammer monkeys.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Eric commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Fascinating, I wish Google or Microsoft or the U.S. Government could fund more such efforts. Eric" href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a66ec5de970b#comment-6a00d835018afd53ef0120a66ec5de970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a66ec5de970b</id>
			<published>2009-11-10T16:42:02Z</published>
			<updated>2009-11-10T16:42:02Z</updated>
			<author>
				<name>Eric</name>
                <uri>http://www.sc2hacks.com</uri>
			</author>
			<summary>Fascinating, I wish Google or Microsoft or the U.S. Government could fund more such efforts. Eric</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Fascinating, I wish Google or Microsoft or the U.S. Government could fund more such efforts.&lt;br /&gt;
Eric&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>GarWarner commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="FireEye does it again! Tremendous job! Its great to see security companies that fight computer crime instead of just profiting..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a6639a30970b#comment-6a00d835018afd53ef0120a6639a30970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a6639a30970b</id>
			<published>2009-11-08T21:37:19Z</published>
			<updated>2009-11-08T21:37:19Z</updated>
			<author>
				<name>GarWarner</name>
                <uri>http://garwarner.blogspot.com/</uri>
			</author>
			<summary>FireEye does it again! Tremendous job! Its great to see security companies that fight computer crime instead of just profiting...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;FireEye does it again!  Tremendous job!  Its great to see security companies that fight computer crime instead of just profiting from it.  You may be small, but you are a significant leader in this area!  Well done!&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>joe blow commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="i would just like to say, that i applaud your actions in getting this botnet shut down. as soon as..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a65f06c4970b#comment-6a00d835018afd53ef0120a65f06c4970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a65f06c4970b</id>
			<published>2009-11-07T03:02:58Z</published>
			<updated>2009-11-07T03:02:58Z</updated>
			<author>
				<name>joe blow</name>
                
			</author>
			<summary>i would just like to say, that i applaud your actions in getting this botnet shut down. as soon as...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;i would just like to say, that i applaud your actions in getting this botnet shut down.  as soon as this one goes down, please keep shutting them all down.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>James McQuaid commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Excellent work Atif!" href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a65ed8fa970b#comment-6a00d835018afd53ef0120a65ed8fa970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a65ed8fa970b</id>
			<published>2009-11-07T01:20:48Z</published>
			<updated>2009-11-07T01:20:48Z</updated>
			<author>
				<name>James McQuaid</name>
                <uri>http://doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork</uri>
			</author>
			<summary>Excellent work Atif!</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Excellent work Atif!&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>tw commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Spamhaus has SBL record indicating that is yopilazankaza.net is pointing to 195.161.113.218, Ref: SBL80926 Great to hear that 174.139.16.50 is..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a65da8ac970b#comment-6a00d835018afd53ef0120a65da8ac970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a65da8ac970b</id>
			<published>2009-11-06T20:41:50Z</published>
			<updated>2009-11-06T20:41:50Z</updated>
			<author>
				<name>tw</name>
                
			</author>
			<summary>Spamhaus has SBL record indicating that is yopilazankaza.net is pointing to 195.161.113.218, Ref: SBL80926 Great to hear that 174.139.16.50 is...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Spamhaus has SBL record indicating that is yopilazankaza.net is pointing to 195.161.113.218, Ref: SBL80926&lt;br /&gt;
Great to hear that 174.139.16.50 is offline. &lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Atif Mushtaq commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="tw, Are you trying to say that &#39;yopilazankaza.net&#39; has started pointing to some IP other than 174.139.16.50. I am not..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a6b29bfb970c#comment-6a00d835018afd53ef0120a6b29bfb970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a6b29bfb970c</id>
			<published>2009-11-06T19:57:26Z</published>
			<updated>2009-11-06T19:57:26Z</updated>
			<author>
				<name>Atif Mushtaq</name>
                <uri>http://blog.fireeye.com</uri>
			</author>
			<summary>tw, Are you trying to say that &#39;yopilazankaza.net&#39; has started pointing to some IP other than 174.139.16.50. I am not...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;tw,&lt;/p&gt;

&lt;p&gt;Are you trying to say that &amp;#39;yopilazankaza.net&amp;#39; has started pointing to some IP other than 174.139.16.50. I am not seeing this change at all, the domain is still pointing to 174.139.16.50 which was taken down by the ISP involved recently. In other words I am not seeing any re-gain attempt made by bot herders so far. May be they are waiting for the right time...&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>tw commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Very nice research--have passed it on to several powers that be. At least one of the domains in the list..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a6b258ee970c#comment-6a00d835018afd53ef0120a6b258ee970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a6b258ee970c</id>
			<published>2009-11-06T18:48:53Z</published>
			<updated>2009-11-06T18:48:53Z</updated>
			<author>
				<name>tw</name>
                
			</author>
			<summary>Very nice research--have passed it on to several powers that be. At least one of the domains in the list...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Very nice research--have passed it on to several powers that be. &lt;br /&gt;
At least one of the domains in the list (yopilazankaza.net) already appears on a new IP address with nameservers associated with Conficker and Braviax. Hope Ozdok efforts to recover simply exposes more of the participants and malware infrastructure. &lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>AlphaCentauri commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Nice work! This is extremely significant, because the biggest obstacle to fighting these botnets is the attitude that &quot;There&#39;s no..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a6b20248970c#comment-6a00d835018afd53ef0120a6b20248970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a6b20248970c</id>
			<published>2009-11-06T18:02:30Z</published>
			<updated>2009-11-06T18:02:30Z</updated>
			<author>
				<name>AlphaCentauri</name>
                <uri>http://ksforum.inboxrevenge.com</uri>
			</author>
			<summary>Nice work! This is extremely significant, because the biggest obstacle to fighting these botnets is the attitude that &quot;There&#39;s no...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Nice work! This is extremely significant, because the biggest obstacle to fighting these botnets is the attitude that &amp;quot;There&amp;#39;s no point trying, it will never work, there are too many of them, none of the other ISP&amp;#39;s would cooperate, there are too many computers running unpatched pirated Windows OS&amp;#39;s,&amp;quot; yadda, yadda.&lt;/p&gt;

&lt;p&gt;Now everyone can see that with knowledgeable planning and a coordinated evening&amp;#39;s work, you can take 264,784 bots off line, with only four C&amp;amp;C IP&amp;#39;s left to take down. It makes it look a lot more feasible to get a whole botnet at once, and puts a lot more pressure on the ISP&amp;#39;s that fail to cooperate. With further coordination between the multiple entities working on the problem, it should be possible to take multiple botnets down simultaneously, greatly reducing the concern about retaliatory attacks against cooperating hosts.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Nart commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Great work! I&#39;m wondering if you guys might post a sort of &quot;lessons learned&quot; on how to do effective notification...." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a65caa63970b#comment-6a00d835018afd53ef0120a65caa63970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a65caa63970b</id>
			<published>2009-11-06T17:18:28Z</published>
			<updated>2009-11-06T17:18:28Z</updated>
			<author>
				<name>Nart</name>
                <uri>http://nartv.org</uri>
			</author>
			<summary>Great work! I&#39;m wondering if you guys might post a sort of &quot;lessons learned&quot; on how to do effective notification....</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Great work! I&amp;#39;m wondering if you guys might post a sort of &amp;quot;lessons learned&amp;quot; on how to do effective notification. What is the best way to contact ISP&amp;#39;s, registrars, and CERTs? What kind of &amp;quot;evidence&amp;quot; do they require to take action? How do they prefer the evidence to be presented? Etc... This would be especially for individual researchers. Thanks. -nart&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>diocyde commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="On a side note, it is truly embarrassing and goddamn shame that it takes a bright SNappy company young upstart..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a6b195a2970c#comment-6a00d835018afd53ef0120a6b195a2970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a6b195a2970c</id>
			<published>2009-11-06T16:01:56Z</published>
			<updated>2009-11-06T16:01:56Z</updated>
			<author>
				<name>diocyde</name>
                <uri>http://diocyde.wordpress.com/</uri>
			</author>
			<summary>On a side note, it is truly embarrassing and goddamn shame that it takes a bright SNappy company young upstart...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;On a side note,  it is truly embarrassing and goddamn shame that it takes a bright SNappy company young upstart such as yourselves to actually make a HUGE impact on the entire security of the Internet.  Larger companies like Symantec, Microsoft, Trend, and McAfee should be embarrassed that they can grasp these simple concepts and take down some of the larger botnets the same way. on a broader scale and with much more speed and tactical surprise.  SHAME on them.  They clearly have the resources to do it.  If you get rid of the background noise, Top 15 largest botnets, you can focus on the smaller more damaging botnets, that at times can raid and pillage a company before they even know what hit them.  Think CoreFlood.  and the over 500 and growing different Zeus networks, Clampi, and ilomo.  &lt;/p&gt;

&lt;p&gt;Did you collaborate with any other vendors or was this a one man show?  Maybe you can partner with someone to Start taking out the top 15 - 1 by 1 until their finances dry up.  Or get some seed money and Payoff and empower 1 or 2 of the largest with bribes, implants into their organization or coersion, to get them to roll or ratt out the leadership on say the bottom 8 botnets.  Typically if they are going to be Russian Eastern Europa based, all the hackers primarily know each other in the under ground over there.&lt;/p&gt;

&lt;p&gt;My suggestion is follow up with the Trend Research report on the Asprox guys.  Trend went literally to their doorstep and then stopped.  They operate with impunity and I would suggest they are NEXT on the SMASHING BLOCK&amp;gt;&lt;/p&gt;

&lt;p&gt;Go for it.  LEAD or DIE.   or just continue to operate and make money but dont do a dam thing about the problem  like most of the other major security companies do.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Sim commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="great job guys! I wish a lot of people will follow your exemple and take down the botnets they are..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a65c5f3b970b#comment-6a00d835018afd53ef0120a65c5f3b970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a65c5f3b970b</id>
			<published>2009-11-06T15:56:52Z</published>
			<updated>2009-11-06T15:56:52Z</updated>
			<author>
				<name>Sim</name>
                
			</author>
			<summary>great job guys! I wish a lot of people will follow your exemple and take down the botnets they are...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;great job guys!&lt;br /&gt;
I wish a lot of people will follow your exemple and take down the botnets they are working on!&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>diocyde commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="This is awesome, however I am concerned about the lack of response from some registrars and ISPs on the abuse..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a65c5a9a970b#comment-6a00d835018afd53ef0120a65c5a9a970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a65c5a9a970b</id>
			<published>2009-11-06T15:52:50Z</published>
			<updated>2009-11-06T15:52:50Z</updated>
			<author>
				<name>diocyde</name>
                <uri>http://diocyde.wordpress.com/</uri>
			</author>
			<summary>This is awesome, however I am concerned about the lack of response from some registrars and ISPs on the abuse...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;This is awesome, however I am concerned about the lack of response from some registrars and ISPs on the abuse and takedown notices.  As you know any gaps could allow for an Update to slip in.  &lt;/p&gt;

&lt;p&gt;It should be possible for you to contact the ISPs for a file extraction pull of the Command and Control backend software (usually PHP) so that you can analyze that and compare it to other C&amp;amp;C consoles)  As well the C&amp;amp;C&amp;#39;s stupidly use the same sites or near IPs for their drop sites.  You may well be able to capture miscreant intel on the CUSTOMERs of the spam services.  Publicising this would go a long way and help demonstrate the volumne of their operations and their cashflows.  &lt;/p&gt;

&lt;p&gt;Additionally IP logs, may be useful coming inbound to the C&amp;amp;C&amp;#39;s if they stupidly are not coming in via chained proxies or some other anon service or botnet authenticated proxy.   Please Do your best and get a copy of the C&amp;amp;C and publish an analysis, this type of intel is sorely lacking.  &lt;/p&gt;

&lt;p&gt;In a perfect cyber warfare style (no freaking lawyer world) if the other ISPs are complicit or obstinate or on the take and try to undermine your efforts, a Sustained DDOS on the few remaining C&amp;amp;Cs would be needed to ensure they stay down (or you can brick the systems if they were dedicated hosts and not virtual hosts, or you can pop the box and block any incoming connections to the interface)&lt;/p&gt;

&lt;p&gt;You could additionally call the local police in that jurisdiction to get them to respond or better yet the FBI could could most likely ensure take down (if they had the will, this is debatable and doubtful)&lt;/p&gt;

&lt;p&gt;Do you have any intel on the origins of the operators?  Is it dedicated or rented out to multiple parties?  What geographic location is the owners or are they globally distributed?&lt;/p&gt;

&lt;p&gt;Hopefully this will go towards more damaging, industry coordinated attacks on Malware infrastructure which as you know if done right, can be enormously successful.  &lt;/p&gt;

&lt;p&gt;You know your doing right when you get DDOS some time in the near future.  Hurt the cash flow and make an impact.&lt;/p&gt;

&lt;p&gt;A great article would be for other providers on how to assemble a evidence package.  Standardizing this for the industry would go a long way.&lt;/p&gt;

&lt;p&gt;Diocyde&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://diocyde.wordpress.com/&quot; rel=&quot;nofollow&quot;&gt;http://diocyde.wordpress.com/&lt;/a&gt; &lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Steven Burn commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="Nice one :o)" href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a6b15c2b970c#comment-6a00d835018afd53ef0120a6b15c2b970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a6b15c2b970c</id>
			<published>2009-11-06T15:01:55Z</published>
			<updated>2009-11-06T15:01:55Z</updated>
			<author>
				<name>Steven Burn</name>
                <uri>http://it-mate.co.uk</uri>
			</author>
			<summary>Nice one :o)</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;Nice one :o)&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>spamislame commented on &#39;Smashing the Mega-d/Ozdok botnet in 24 hours&#39;</title>
			<link rel="alternate" type="text/html" title="I am uncertain if this is related but a forum I maintain with several colleagues was under a very severe,..." href="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html?cid=6a00d835018afd53ef0120a6b150c3970c#comment-6a00d835018afd53ef0120a6b150c3970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a6b150c3970c</id>
			<published>2009-11-06T14:49:23Z</published>
			<updated>2009-11-06T14:49:23Z</updated>
			<author>
				<name>spamislame</name>
                <uri>http://ikillspammerz.blogspot.com/</uri>
			</author>
			<summary>I am uncertain if this is related but a forum I maintain with several colleagues was under a very severe,...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/11/smashing-the-ozdok.html">&lt;p&gt;I am uncertain if this is related but a forum I maintain with several colleagues was under a very severe, sustained attack until sometime last night. This may have coincided with your efforts.&lt;/p&gt;

&lt;p&gt;Either way this is excellent news, and as usual extremely good research.&lt;/p&gt;

&lt;p&gt;SiL / IKS / concerned citizen&lt;/p&gt;</content>
		</entry>
	
</feed>

<!-- ph=1 -->