Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 34 guests and 3 members online
You are here:
Home
Resources
News from the Outside World
new botnet, largest ever
EH-Net
May 24, 2013, 10:38:30 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
News from the Outside World
(Moderator:
don
) >
new botnet, largest ever
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: new botnet, largest ever (Read 7376 times)
0 Members and 1 Guest are viewing this topic.
pseud0
Recruiters
Full Member
Offline
Posts: 208
new botnet, largest ever
«
on:
April 07, 2008, 10:16:15 AM »
These guys are not kidding around:
http://www.darkreading.com/document.asp?doc_id=150292&WT.svl=news1_1
-researchers have found it on a variety of system in Fortune 500 companies
-at this point it is undetectable using normal AV products
-500k+ machines
-communicates using custom encrypted protocols
Quote
SAN FRANCISCO -– RSA 2007 Conference –- A new botnet twice the size of Storm has ballooned to an army of over 400,000 bots, including machines in the Fortune 500, according to botnet researchers at Damballa. (See The World's Biggest Botnets and MayDay! Sneakier, More Powerful Botnet on the Loose.)
The so-called Kraken botnet has been spotted in at least 50 Fortune 500 companies and is undetectable in over 80 percent of machines running antivirus software. Kraken appears to be evading detection by a combination of clever obfuscation techniques, including regularly updating its binary code and structuring the code in such a way that hinders any static analysis, says Paul Royal, principal researcher at Damballa.
"It's easy to trace but slow to get antivirus coverage. It seems to imply [the creators] have a good understanding of how AV tools operate and how to evade them," Royal says.
Kraken's successful infiltration of major enterprises is a wakeup call that bots aren't just a consumer problem. Damballa and other botnet experts over the past few months have seen an unsettling rise in bot infections in enterprises. (See Bots Rise in the Enterprise.)
Royal says like Storm, Kraken so far is mostly being used for spamming the usual scams -- high interest loans, gambling, male enhancement products, pharmacy advertisements, and counterfeit watches, for instance. "But given that it updates its binary, there's no reason it couldn't update itself to a binary that does other things," Royal says. "I'm wondering where this thing is going to go."
Damballa predicts that even now that Kraken has been outed, it will continue growing at least in the near-term -- up to at least 600,000 new bots by mid-April. Its bots are prolific, too: The firm has seen single Kraken bots sending out up to 500,000 pieces of spam in a day.
Just how Kraken is infecting machines is still unclear, but Royal says the malware seems to appear as an image file to the victim. When the victim tries to view the image, the malware is loaded onto his or her machine. "We know the picture... ends in an .exe, which is not shown" to the user, Royal says.
Royal didn't rule out the possibility that Kraken could be some sort of Storm spinoff since Damballa had not performed any analysis of any potential "intersections" between the two botnets, he says.
Kraken's bots and command and control servers communicate via customized UDP and TCP-based protocols, he says, and the botnet has built-in redundancy features that automatically generate new domain names if a C&C server gets shut down or becomes disabled. "And the actual payload is encrypted," Royal says.
Damballa first noticed Kraken late last year, but says early variants of the botnet appear to date back to late 2006. The primary C&C servers are hosted in France, Russia, and the U.S., according to Damballa.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
Andrew Waite
Hero Member
Offline
Posts: 928
Re: new botnet, largest ever
«
Reply #1 on:
April 07, 2008, 10:25:09 AM »
Pseudo,
thanks for the link. I've just read the same story on
The Register
and was looking for more technical details on implemenations/capabilities etc.
I'll be interested to see how soon AV vendors manage decent coverage of this. Unfortunately newer malware techniques seem to be leaving traditional defense mechanisms behind.
One thing that does surprise me from this is that there appears to be a heirachical C&C structure, so this may not last long once it hits noteriety.
<edit: just re-read article, looks like it's already got this base covered>
But as it's already reaching a supposed half million infections it may have more tricks up its sleeve yet.
Seems like the war rages on....
«
Last Edit: April 07, 2008, 10:27:48 AM by RoleReversal
»
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
shawal
Jr. Member
Offline
Posts: 88
Re: new botnet, largest ever
«
Reply #2 on:
April 07, 2008, 11:09:06 AM »
nice one Pseudo
I will email this to my managmenet first thing in the morning tommorow, they are still believe that we are secure. the false sense of security is the threat. having antiviruses, and the state of the art ips,ids,firewalls, and vpns does not help much if we can not understand the 0day issues, and the amount of work the bad guys are investing in new attack vectors.
Logged
RHCE, GIAC GCIH.
g00d_4sh
Sr. Member
Offline
Posts: 394
Re: new botnet, largest ever
«
Reply #3 on:
April 08, 2008, 07:47:29 PM »
If I understood the article, which I read earlier when it first came out, the botnet uses the method of continually evolving it's binary, or simply pushing out slightly changed binary to all it's nodes. Kind of makes traditional AV that is signature based worthless against it. I was reading about one a month ago or so that altered it's code as it moved from machine to machine, I don't think Kraken does that from what I have thus far read. If I understand the workings of that correctly, until behavior analysis style AV becomes more popular this isn't going to be protected against.
On a related note, just started trying out Comodo firewall at home, anyone else use it? Seems kind of nifty, I've been using the free Zonealarm firewall for years. The built in registry lock seems interesting, kind of like Tea Timer from Spybot, but less buggy interface wise. I'm assuming a decent personal firewall set up correctly would be at least more helpful than AV vs a bot infection, then again there is the rootkit you probably don't find anyway heh.
Logged
"Bad.. Good? I'm the guy with the gun"
dean
Guest
Re: new botnet, largest ever
«
Reply #4 on:
April 08, 2008, 08:40:46 PM »
Dynamic binary repacking and code obfuscation and static/dynamic analysis techniques are not new. Most bots have some level of each today. Storm's binary changes approximately every 15minuts or so. I ran an analysis on about 60 binaries of Storm collected over a period of one hour and from different url's and about 30% were unique.
As for Kraken, there is talk that it may be FUD on the part of Damballa.
""We've taken a look at this and it seems the Damballa guys are into rebranding, and that they've simply taken Bobax" and presented it as Kraken, said Dmitri Alperovitch, director of intelligence analysis at Secure Computing, also based in Atlanta."
http://blog.washingtonpost.com/securityfix/2008/04/kraken_creates_a_clash_of_the.html
Some more links:
http://www.incidents.org/diary.html?storyid=4256
http://emergingthreats.net/
- includes links to other sites with in.
Either way it's interesting to note that bots and the management of them is evolving and so detection is getting more difficult at both a network and host level. Traditional methods of anti virus or anti spyware are limited and so use of honeynets and honey-clients are evolving from being research tools to valid detection and mitigation solutions.
dean
Logged
shawal
Jr. Member
Offline
Posts: 88
Re: new botnet, largest ever
«
Reply #5 on:
April 08, 2008, 11:53:54 PM »
g00d_4sh ,
firewalls do prevent from most of the threats, however they are not the key factor in preventing this. enterprise/personal firewall would still most likely allow port 80 trafic to pass. most likely you have asked the personal firewal to always trust your favourite browser. so if the bot agent/trojan/malware can inject itself onto the browser code, or even spoof itself as it is the firewall is uselss
Dean,
Interesting URLs, need to investigate this more when i have more time, and collect some storm speciemens from the wild net
Logged
RHCE, GIAC GCIH.
Andrew Waite
Hero Member
Offline
Posts: 928
Re: new botnet, largest ever
«
Reply #6 on:
April 09, 2008, 04:44:27 AM »
Dean,
Quote from: dean on April 08, 2008, 08:40:46 PM
I ran an analysis on about 60 binaries of Storm collected over a period of one hour and from different url's and about 30% were unique.
Sounds like you've been having some fun, are you able/willing to tell what tools/processes your are using to collect your samples?
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
dean
Guest
Re: new botnet, largest ever
«
Reply #7 on:
April 09, 2008, 09:04:19 AM »
Quote
Sounds like you've been having some fun, are you able/willing to tell what tools/processes your are using to collect your samples?
I use a set of perl scripts I've written to download the binaries and compare hashes on those binaries. I also use similar scripts to perform lookups and geo-ip mapping to determine the locations of compromised machines. The urls/ip addresses come from various spam emails that I collect, honeypots like nepenthes and client honeypots like honey-hpc.
If anyone is interested I'll post some of the scripts.
dean
Logged
shawal
Jr. Member
Offline
Posts: 88
Re: new botnet, largest ever
«
Reply #8 on:
April 09, 2008, 10:51:07 AM »
Dean,
is that an XSS test in your signature?
Logged
RHCE, GIAC GCIH.
dean
Guest
Re: new botnet, largest ever
«
Reply #9 on:
April 09, 2008, 02:04:14 PM »
It could be but the sig is more of a joke.
type:
javascript:alert('%52%54%46%4D')
in your browsers navigation bar.
It will decode the hex for you.
dean
Logged
dean
Guest
Re: new botnet, largest ever
«
Reply #10 on:
April 09, 2008, 04:19:41 PM »
In follow up to the original post.
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9076278&source=NLT_PM&nlid=8
Joe Stewart presented his findings at RSA on the top botnets.
dean
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: new botnet, largest ever
«
Reply #11 on:
April 10, 2008, 02:10:06 AM »
Dean,
Quote from: dean on April 09, 2008, 02:04:14 PM
javascript:alert('%52%54%46%4D')
nice
Thanks for the link to Keizer's article, makes for interesting reading.
One aspect that always surprises me witht these sorts of articles is the numbers of infections etc. that get quoted as fact. I might be missing a trick, but is there any more to these figures than educated guesswork? I just can't see how any of these stats could be claimed with any definity.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
dean
Guest
Re: new botnet, largest ever
«
Reply #12 on:
April 10, 2008, 08:37:27 AM »
The numbers are an estimate but they can be pretty accurate. It depends on how you do the detection. Arbor Networks has a worldwide series of Honeypots in place at most of the large ISPs. This with the netflow they use for doing analysis can give a pretty good indication of the spread/scale of an infection. Have a look at
http://atlas.arbor.net/
Secureworks seem to have developed signatures for the smtp engines the bots use and detect the traffic that way using spam traps.
Trustedsouce have this page that tracks the spread of storm:
http://www.trustedsource.org/TS?do=threats&subdo=storm_tracker
For a fastflux/round robin DNS enabled botnet I use simple dns queries of a malware domain but query against multiple nameservers to determine the number of unique ip addresses associated with that domain. By running this over a period of time, until you see the rate of infection begin to decline, you can estimate the scale of the botnet.
I also sometimes run a script that will masquerade as a bot in a channel and collect information on the size of the channel. I've also seen research on P2P based botnets where the P2P network is 'crawled'.
None of this is perfect as you are dealing with changing bot code, new domains, time zones, etc... but if you trend it out over time you can get a pretty good indication of the size of the botnet.
I posted a simple lookup script in another post that will run continuous lookups on a domain and map the ip to country. It's interesting just to run it on a domain to see the results.
dean
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: new botnet, largest ever
«
Reply #13 on:
April 10, 2008, 10:44:51 AM »
Dean,
thanks for the response and links, looks like I've got some extra research to do.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.