Srizbi rootkit removal instructions

FireEye researchers
have tested and thus recommend the following steps for victims of Srizbi to remove the infection. Some basic level of expertise with
Windows system administration is required to perform these steps.
This material is provided “as is”, with absolutely no warranty expressed or implied.

Continue reading »

Not to sound the panic alarm…

Not to sound the panic alarm, but it appears that I was slightly off base earlier with my comment that the Srizbi fallback C&C domains were hard coded in the sample. It’s true that the seed was hard coded, and that multiple samples had the same seed, but the domain name generated appears to be a function of the local time as well, which explains the ~36 hour window I was seeing. There do appear to be some retry timeouts as well that dont kick in exactly as the day begins, so this may be another reason it wasn’t immediately evident earlier.

Continue reading »

Rustock’s new home in cyberspace… Russia!

As we predicted in an earlier post, Rustock began it’s global update last night to change the Command and Control servers from McColo to a data center in Russia. We believe that the Rustock controllers don’t expect McColo to be very stable in the near future, so they are hedging their bets and moving the C&C’s to a different provider.

Continue reading »

McColo found a new upstream provider (update)

UPDATE: Although the below is still interesting data, Telia has withdrawn the routes for McColo’s net blocks

As we were monitoring Srizbi and Rustock in our labs today, all of a sudden a sample from the lab started connecting to a routable McColo C&C server. This McColo hosted C&C server, with an IP of 208.66.194.22, was again fully responding to Rustock. It appears they’re back! The best part about this story is that they haven’t physically moved their servers… they’re still in Market Post Tower in sunny San Jose. Telia (whom I contacted) appears to have low enough standards that they are providing McColo a new cross-connect.

Continue reading »

McColo’s Video Debut

While looking for more information on the recent Mccolo shutdown, the research team here came across something very interesting. We found a blog with the name of ‘micaelale blog’ which had an article about the recent take down.

hxxp://micaelale.vox.com/library/post/mccolo.html?_c=feed-atom (careful, it’s malicious!)

Continue reading »

100,000+ Srizbi IPs detected in 24 hours, Part 1

The shutdown of the McColo Corporation left hundreds of thousands of Bots without a Command and Control server to which to connect. The research team here at HQ decided to look into the fallback mechanism that one of the top Botnets, Srizbi, employed. We assumed that there was a contingency plan that was enacted once the primacy C&C was down for an extended period of time. It appears we were correct in this assumption, but we were shocked, to say the very least, at the implementation. This is part 1 of an N part series about Botnet fallback channels.

Continue reading »

McColo shutdown Nov 11, 2008 16:23 EST

Something funny happened while I was writing another anti-McColo article today… the domains stopped responding. What I was going to write about was how Rustock changed its Command and Control server to an IP previously used by Pushdo/Cutwail. This is clearly not a coincidence and shows again that these Botnets are run by the same group.

Continue reading »

McColo (still) hosting Rustock C&C

A month ago we wrote that McColo was hosting a Rustock Command and Control server on 208.72.168.191. I wish I could report that Hurricane Electric or Global Crossing, their two upstream providers, had stopped routing these clowns, but unfortunately, that is not the case.

Continue reading »