McColo found a new upstream provider (update)

UPDATE: Although the below is still interesting data, Telia has withdrawn the routes for McColo’s net blocks

As we were monitoring Srizbi and Rustock in our labs today, all of a sudden a sample from the lab started connecting to a routable McColo C&C server. This McColo hosted C&C server, with an IP of 208.66.194.22, was again fully responding to Rustock. It appears they’re back! The best part about this story is that they haven’t physically moved their servers… they’re still in Market Post Tower in sunny San Jose. Telia (whom I contacted) appears to have low enough standards that they are providing McColo a new cross-connect.

Continue reading »

McColo’s Video Debut

While looking for more information on the recent Mccolo shutdown, the research team here came across something very interesting. We found a blog with the name of ‘micaelale blog’ which had an article about the recent take down.

hxxp://micaelale.vox.com/library/post/mccolo.html?_c=feed-atom (careful, it’s malicious!)

Continue reading »

100,000+ Srizbi IPs detected in 24 hours, Part 1

The shutdown of the McColo Corporation left hundreds of thousands of Bots without a Command and Control server to which to connect. The research team here at HQ decided to look into the fallback mechanism that one of the top Botnets, Srizbi, employed. We assumed that there was a contingency plan that was enacted once the primacy C&C was down for an extended period of time. It appears we were correct in this assumption, but we were shocked, to say the very least, at the implementation. This is part 1 of an N part series about Botnet fallback channels.

Continue reading »

McColo shutdown Nov 11, 2008 16:23 EST

Something funny happened while I was writing another anti-McColo article today… the domains stopped responding. What I was going to write about was how Rustock changed its Command and Control server to an IP previously used by Pushdo/Cutwail. This is clearly not a coincidence and shows again that these Botnets are run by the same group.

Continue reading »

Silent Storm or Silence before the Storm…

Researchers who monitor Storm strictly from a SPAM aspect have come to a
conclusion that Storm is dead (for now), but actually from a botnet point of view, Storm is
very much alive and kicking. Read on to see our analysis about how we’ve been able to see live Storm bots.

There is an old saying that says something like “The best way to kill a bear is to use his own power against him.”

This is precisely what happened with Storm. People in and around the industry talked at length about the beauty of the Storm Peer to Peer architecture and its use of fast-flux networks. But, in fact, Storm’s P2P communication was the main reason that the security community had an opportunity to monitor, detect, and decrypt Storm traffic, as all inter-Bot traffic was very noisy. Going one step further, the easily crackable communication gave those with more nefarious intentions the ability to poison, or straight take over, Storm bots.

I decided to write this article as I read the findings from Jeremy’s article published on 5 October 2008.
http://www.sudosecure.net/archives/264

Continue reading »

New Axis of Evil – Storm, Pushdo and Trojan.Exchanger

Over the past few months, the FireEye research team has seen a gradual but steady decline in the sheer number of Bots controlled by the spam king Storm. Quietly, Srizbi and Rustock have eclipsed Storm in our labs and at our (quicky growing!) customer base. Last month we found a very close, if not definitive, relationship between Srizbi, Pushdo, Rustock, and Mega-D. You can review our findings, as well as some of our peers confirming our discoveries below:

https://www.fireeyesolution.com/research/2008/08/srizbi-and-ru-1.htm
https://www.fireeyesolution.com/research/2008/08/srizbi-and-rust.html
http://www.darkreading.com/document.asp?doc_id=162056&WT.svl=news2_1
http://www.marshal.com/trace/traceitem.asp?article=751

The Botnet connections appear to go deeper - we have discovered that there is a direct connection between Storm, Pushdo and Trojan.Exchanger as well.

Continue reading »

Srizbi actively stealing data

Srizbi and the similar top Botnets are currently mainly used to send spam. It is very infrequent that we see these Bots doing anything *but* spamming. It’s happening now, we have recently seen Srizbi going beyond just regular spam and getting involved into information stealing.

Continue reading »

Srizbi and Rustock: Family Feud or Sibling Rivalry? Part II

FireEye recently dove into the world of spam email Botnets to further strengthen our belief that Botnets like Srizbi, Pushdo, and Rustock, although having completely different C&C architectures, are operated by same group.

This go around, we looked at the servers that control these Botnets and spam created from live Bots in our lab. As part of this investigation, we analyzed multiple malware samples of these Botnets in our both virtual and real lab environments to extract the relevant C&C locations. When we compared the C&C IPs being used by these three Botnets, we were surprised to see that all three were using servers in the same colocation facility, and that this facility was fairly well known (by a quick Google search) to have been used for malicious activities in the past.

Continue reading »