Vulnerabilities / Threats

3/31/2011
02:17 PM
50%
50%

Trend Micro Nukes Zeus Botnet Server

PayPal, eBay, and the customers of at least 15 banks were targeted by the eliminated botnet.

How Firesheep Can Hijack Web Sessions
(click image for larger view)
Slideshow: How Firesheep Can Hijack Web Sessions
Antivirus security company Trend Micro on Wednesday said that it eliminated -- or "sinkholed" -- a Zeus botnet command-and-control (C&C) server.

"In February 2011, we successfully collaborated with CDMON, a registrar, to gain control of a Zeus botnet C&C server, thereby rendering it ineffective," said Trend Micro security researchers David Sancho and Rainer Link in a blog post.

According to a report (pdf) released by Trend Micro that detailed the takedown in greater detail, this particular Zeus botnet targeted customers of 15 banks in the United States, South America, and Europe, as well as multiple online payment providers, including eBay and PayPal.

"The lack of coherence regarding the targeted banks and the locations of the infected computers suggests that the botmaster just left a default configuration while spreading the Trojan around his own geographical area," according to the report. "This was a sign that he was still an amateur."

Zeus is a crimeware toolkit that's used to build botnets and steal sensitive financial information from people's PCs. There are multiple "Zeus botnets" in the wild, each of which reports back to the botmaster that created it.

Indeed, according to the Zeus Tracker, which is monitoring more than 500 Zeus C&C servers, there are at least 44 Zeus C&C servers running in Russia, 35 in the United States, 29 in Romania, and 28 in the Ukraine. As that suggests, even though Zeus also appears to have merged with SpyEye, a former competitor, people are still using the standalone Zeus malware toolkit.

The botnet sinkholed by Trend Micro appeared to have originated in the Americas. "We found that over 95% of the inbound requests to the C&C server came from South America, particularly from Mexico," said the Trend Micro researchers. "This indicates that the bot may have originated from Latin America or was created using the Spanish language. Its creator may have decided to target banks in Mexico and Chile as well, as these often still used single-factor authentication to secure their customers' accounts."

For the takedown, domain registrar CDMON -- through which the botmaster had registered the sites for his Zeus-driven attacks -- helped Trend Micro impersonate the real C&C server. "CDMON was kind enough to replace the server's original address with that of our own machine," according to the Trend Micro report. "This was enough to tell the bot clients that they should communicate with us instead of the cybercriminal." The security company said it collected three weeks' worth of data for analysis before deactivating the botnet.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Darn - typed UNICORN instead of UNICODE.  
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.