Zoom-In to Pushdo CnCs….

[Dec, 8th, UPDATE] Today NOC4HOSTS responded our abuse notifications and pulled the plug for all Pushdo CnC servers as mentioned in this post along with many Grum CnC as mentioned here. We really say thanks to NOC4HOSTS for their positive response.

[Dec, 4th, UPDATE] One more Cnc within NOC4HOSTS 74.50.113.92.

[Dec, 4th, UPDATE] One more IP from NOC4HOSTS 74.50.120.87 is found to be serving Cutwail. As in other cases this host is continuously delivering new SPAM templates hence becoming a cause of recent increase in Wordwide SPAM.

[UPDATE] We have Identified one more Cutwail CnC (74.50.125.72) hosted at NOC4HOSTS. So far NOC4HOSTS has not responded to any of the abuse notifications sent by FireEye.

In my previous post, I discussed different aspects of Pushdo’s command and control
architecture and its fallback mechanism. Now I will discuss some datacenters which are currently hosting Pushdo and Cutwail command/control servers.

Let’s first discuss the Cutwail CnCs, as these are the ones which supply daily SPAM ammunition to bots all over the world in the form of new templates. In the absence of these servers, the Pushdo botnet will no longer be able to send SPAM.

One such server is currently located in Estonia hosted by STARLINE WEB SERVICES having an IP address 92.62.100.95:1995.
This is the same data center used by Srizbi few days back in an attempt
to regain its control. This attempt did not prove to be very fruitful after
a quick response by the community and Estonian CERT.

UPDATE: Estonia has pulled this server offline and we sincerely appreciate their swift action.

Continue reading »

Cut the Cutwail…!

As Srizbi and Rustock are (temporarily) shutdown, there are only a few botnets
left which are still able to communicate with their CnCs, and hence are able to send SPAM. This group of Botnets is
some portion of Pushdo/Cutwail and Bobax/Kraken.

Marshal TRACE’s recent analysis of SPAM distribution with respect to different
botnets shows that currently Pushdo is the main source of worldwide SPAM in the absence of Srizbi and Rustock. Shutting down Pushdo (even temporarily) would mean
more days without SPAM, just as we saw with the earlier shutdowns.

Continue reading »

Srizbi control regained by original owner

UPDATE: The Estonia based Command and Control servers have been kicked offline. I’ll post more details of how this happened when I get the go ahead from the responsible party. The below information is still valid, but the addresses listed (except for the one in Frankfurt) are no longer reachable.

Srizbi has returned from the dead and has begun updating all its Bots with a fresh, new binary. The worldwide update began just a few hours ago. The new Command and Control servers are located in Estonia, and the domains registered through a registrar in Russia.

Continue reading »

Rustock is Back…

UPDATE: There was an abuse notification sent to LayeredTech by my co-researcher Alex Lanstein earlier this morning. As a result LayeredTech seems to have pulled the server. ‘sdx3Fs5B.info’ still has an A entry for the IP, but it is no longer responding. Perhaps colos are starting to pay more attention to botnets and abuse notifications?

—————————————-

Rustock and its SPAM are back. All Rustock variants which were able to update themselves during McColo’s brief return on 15 Nov 2008, are back with new nasty SPAM campaigns.

The updated Rustock binaries in our lab since the shutdown have been trying to connect to different CnC servers to look for more commands, but either the domains were not resolving or the servers were not acknowledging Rustock’s login requests. This no longer appears to be the case. Today, one of the new CnC servers, ‘sdx3Fs5B.info’ which is currently resolving to 72.233.114.74 (abuse notification to LayeredTech sent), started to respond. After accepting the login, the next instruction was to download new spam templates. Immediately after receiving the templates, the samples started sending SPAM.

Continue reading »

Srizbi rootkit removal instructions

FireEye researchers
have tested and thus recommend the following steps for victims of Srizbi to remove the infection. Some basic level of expertise with
Windows system administration is required to perform these steps.
This material is provided “as is”, with absolutely no warranty expressed or implied.

Continue reading »

Not to sound the panic alarm…

Not to sound the panic alarm, but it appears that I was slightly off base earlier with my comment that the Srizbi fallback C&C domains were hard coded in the sample. It’s true that the seed was hard coded, and that multiple samples had the same seed, but the domain name generated appears to be a function of the local time as well, which explains the ~36 hour window I was seeing. There do appear to be some retry timeouts as well that dont kick in exactly as the day begins, so this may be another reason it wasn’t immediately evident earlier.

Continue reading »