More on McColo and Rogues

There doesn’t seem to be a day that goes by that I don’t have something new to add on McColo. It’s not that I am trying to target their fine colocation facility, and it’s not that I have a thing against Scotland (har har), it’s just that our appliance keeps detecting more and more badness coming out of their subnets.

Today I’d like to briefly mention a couple examples of what McColo is doing that no one else is talking about. I’ll be doing this in a couple parts just to break up the content.

Continue reading »

Rogue.AntiVirus2009 hosted by McColo

There's a segment of our Beta customers who have a data sharing
agreement with us, wherein they allow the appliance to send up the
malicious URLs and Botnet activity that it has discovered. 

I wanted to
take a quick poke at some of these URLs to see what they were
exploiting, where they were hosted, whether they were "dual use" or
not, etc. 

Continue reading »

Silent Storm or Silence before the Storm…

Researchers who monitor Storm strictly from a SPAM aspect have come to a
conclusion that Storm is dead (for now), but actually from a botnet point of view, Storm is
very much alive and kicking. Read on to see our analysis about how we’ve been able to see live Storm bots.

There is an old saying that says something like “The best way to kill a bear is to use his own power against him.”

This is precisely what happened with Storm. People in and around the industry talked at length about the beauty of the Storm Peer to Peer architecture and its use of fast-flux networks. But, in fact, Storm’s P2P communication was the main reason that the security community had an opportunity to monitor, detect, and decrypt Storm traffic, as all inter-Bot traffic was very noisy. Going one step further, the easily crackable communication gave those with more nefarious intentions the ability to poison, or straight take over, Storm bots.

I decided to write this article as I read the findings from Jeremy’s article published on 5 October 2008.
http://www.sudosecure.net/archives/264

Continue reading »

New Axis of Evil – Storm, Pushdo and Trojan.Exchanger

Over the past few months, the FireEye research team has seen a gradual but steady decline in the sheer number of Bots controlled by the spam king Storm. Quietly, Srizbi and Rustock have eclipsed Storm in our labs and at our (quicky growing!) customer base. Last month we found a very close, if not definitive, relationship between Srizbi, Pushdo, Rustock, and Mega-D. You can review our findings, as well as some of our peers confirming our discoveries below:

https://www.fireeyesolution.com/research/2008/08/srizbi-and-ru-1.htm
https://www.fireeyesolution.com/research/2008/08/srizbi-and-rust.html
http://www.darkreading.com/document.asp?doc_id=162056&WT.svl=news2_1
http://www.marshal.com/trace/traceitem.asp?article=751

The Botnet connections appear to go deeper - we have discovered that there is a direct connection between Storm, Pushdo and Trojan.Exchanger as well.

Continue reading »

Srizbi actively stealing data

Srizbi and the similar top Botnets are currently mainly used to send spam. It is very infrequent that we see these Bots doing anything *but* spamming. It’s happening now, we have recently seen Srizbi going beyond just regular spam and getting involved into information stealing.

Continue reading »

Srizbi and Rustock: Family Feud or Sibling Rivalry? Part II

FireEye recently dove into the world of spam email Botnets to further strengthen our belief that Botnets like Srizbi, Pushdo, and Rustock, although having completely different C&C architectures, are operated by same group.

This go around, we looked at the servers that control these Botnets and spam created from live Bots in our lab. As part of this investigation, we analyzed multiple malware samples of these Botnets in our both virtual and real lab environments to extract the relevant C&C locations. When we compared the C&C IPs being used by these three Botnets, we were surprised to see that all three were using servers in the same colocation facility, and that this facility was fairly well known (by a quick Google search) to have been used for malicious activities in the past.

Continue reading »

Kraken Botnet - A detailed analysis

The biggest vulnerabilities facing the world today are not buffer overruns, but the carbon-based life form sitting between the keyboard and chair. Kraken has proven that yet again. Despite the naming and size controversy, we believe Kraken represents a significant malware threat, that if left unchecked, has the potential to cause businesses and consumers damages more severe than simply spamming.

Continue reading »