FireEye Malware Intelligence Lab - Botnet studies

No explicit questions like "how do I hack xxx.com" please!
Post Reply
User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

FireEye Malware Intelligence Lab - Botnet studies

Post by DNR »

http://blog.fireeye.com/research/2009/0 ... beast.html

"The purpose of this series of articles is very simple, to give our readers an idea about the current geographical distribution of command and control coordinates for the some of the top botnets. Based on this data I'll try to estimate whether it is possible to shutdown these botnets by puling the plug for these servers. The Botnets which will be discussed in these articles are Pushdo, Xarvester, Rustock, Koobface and Ozdok. These stats are based on my sandnet logs for the last 3 months or so."

http://blog.fireeye.com/research/2009/0 ... rt-ii.html

"In this second part of the series I will try to analyze the command and control structure/coordinates for another famous botnet, Koobface. This article is not a detailed analysis of the malware itself but covers mostly its botnet aspect. "

http://blog.fireeye.com/research/2009/1 ... ozdok.html

"In my previous article, I talked about the Ozdok command and control architecture and its fallback mechanisms in great detail. That article was an attempt to highlight different approaches to take down this botnet theoretically. But when it comes to the actual shutdown, it's far more complex than just finding out the command and control server coordinates and fallback mechanisms. An actual shut down attempt requires someone to take the initiative and start a combined effort involving third parties like ISPs, registries, registrars, etc. "
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

nice find man... :D

here is a very interesting site about botnets:
http://www.shadowserver.org
I've joined them and can now report bots via web iface... 8)
Image

Post Reply