Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Jan 2009 Free Giveaway Sponsor - Black Hat DC
Scooby Doo and the Crypto Caper - Answers and Winners
Daemon - A Contest Revealed
Hacking: The Art of Exploitation 2nd Edition
Nov 2008 Free Giveaway - Winners
Dec 2008 Free Giveaway Sponsor - SANS
Santa Claus is Hacking to Town
Plug-N-Play Network Hacking
Nov 2008 Free Giveaway Sponsor - CWNP
Daemon - A Contest Begins Now
It Happened One Friday - Answers and Winners
Daemon - A Contest
Scooby Doo and the Crypto Caper
MS Blue Hat Hackers Headline Chicago Security Con
The Pen Testing Perfect Storm Webcast Series with Skoudis, Wright, Johnson
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 22 guests and 1 member online
EH-Net Donations
Enter Amount:
$
CAD
USD
GBP
AUD
JPY
EUR
Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
Resources
News from the Outside World
new botnet, largest ever
Ethical Hacker Community Forums
January 08, 2009, 07:05:45 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100!
www.chicagocon.com/content/view/103/51/
Home
Help
Calendar
Login
Register
Ethical Hacker Community Forums
>
Resources
>
News from the Outside World
(Moderator:
don
) >
new botnet, largest ever
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: new botnet, largest ever (Read 3122 times)
0 Members and 1 Guest are viewing this topic.
pseud0
Full Member
Offline
Posts: 154
new botnet, largest ever
«
on:
April 07, 2008, 10:16:15 AM »
These guys are not kidding around:
http://www.darkreading.com/document.asp?doc_id=150292&WT.svl=news1_1
-researchers have found it on a variety of system in Fortune 500 companies
-at this point it is undetectable using normal AV products
-500k+ machines
-communicates using custom encrypted protocols
Quote
SAN FRANCISCO -– RSA 2007 Conference –- A new botnet twice the size of Storm has ballooned to an army of over 400,000 bots, including machines in the Fortune 500, according to botnet researchers at Damballa. (See The World's Biggest Botnets and MayDay! Sneakier, More Powerful Botnet on the Loose.)
The so-called Kraken botnet has been spotted in at least 50 Fortune 500 companies and is undetectable in over 80 percent of machines running antivirus software. Kraken appears to be evading detection by a combination of clever obfuscation techniques, including regularly updating its binary code and structuring the code in such a way that hinders any static analysis, says Paul Royal, principal researcher at Damballa.
"It's easy to trace but slow to get antivirus coverage. It seems to imply [the creators] have a good understanding of how AV tools operate and how to evade them," Royal says.
Kraken's successful infiltration of major enterprises is a wakeup call that bots aren't just a consumer problem. Damballa and other botnet experts over the past few months have seen an unsettling rise in bot infections in enterprises. (See Bots Rise in the Enterprise.)
Royal says like Storm, Kraken so far is mostly being used for spamming the usual scams -- high interest loans, gambling, male enhancement products, pharmacy advertisements, and counterfeit watches, for instance. "But given that it updates its binary, there's no reason it couldn't update itself to a binary that does other things," Royal says. "I'm wondering where this thing is going to go."
Damballa predicts that even now that Kraken has been outed, it will continue growing at least in the near-term -- up to at least 600,000 new bots by mid-April. Its bots are prolific, too: The firm has seen single Kraken bots sending out up to 500,000 pieces of spam in a day.
Just how Kraken is infecting machines is still unclear, but Royal says the malware seems to appear as an image file to the victim. When the victim tries to view the image, the malware is loaded onto his or her machine. "We know the picture... ends in an .exe, which is not shown" to the user, Royal says.
Royal didn't rule out the possibility that Kraken could be some sort of Storm spinoff since Damballa had not performed any analysis of any potential "intersections" between the two botnets, he says.
Kraken's bots and command and control servers communicate via customized UDP and TCP-based protocols, he says, and the botnet has built-in redundancy features that automatically generate new domain names if a C&C server gets shut down or becomes disabled. "And the actual payload is encrypted," Royal says.
Damballa first noticed Kraken late last year, but says early variants of the botnet appear to date back to late 2006. The primary C&C servers are hosted in France, Russia, and the U.S., according to Damballa.
Logged
CISSP, CISM
RoleReversal
Hero Member
Offline
Posts: 507
Re: new botnet, largest ever
«
Reply #1 on:
April 07, 2008, 10:25:09 AM »
Pseudo,
thanks for the link. I've just read the same story on
The Register
and was looking for more technical details on implemenations/capabilities etc.
I'll be interested to see how soon AV vendors manage decent coverage of this. Unfortunately newer malware techniques seem to be leaving traditional defense mechanisms behind.
One thing that does surprise me from this is that there appears to be a heirachical C&C structure, so this may not last long once it hits noteriety.
<edit: just re-read article, looks like it's already got this base covered>
But as it's already reaching a supposed half million infections it may have more tricks up its sleeve yet.
Seems like the war rages on....
«
Last Edit: April 07, 2008, 10:27:48 AM by RoleReversal
»
Logged
A little bit of sanity:
http://www.infosanity.co.uk
shawal
Jr. Member
Offline
Posts: 86
Re: new botnet, largest ever
«
Reply #2 on:
April 07, 2008, 11:09:06 AM »
nice one Pseudo
I will email this to my managmenet first thing in the morning tommorow, they are still believe that we are secure. the false sense of security is the threat. having antiviruses, and the state of the art ips,ids,firewalls, and vpns does not help much if we can not understand the 0day issues, and the amount of work the bad guys are investing in new attack vectors.
Logged
RHCE, GIAC GCIH.
g00d_4sh
Sr. Member
Offline
Posts: 296
Re: new botnet, largest ever
«
Reply #3 on:
April 08, 2008, 07:47:29 PM »
If I understood the article, which I read earlier when it first came out, the botnet uses the method of continually evolving it's binary, or simply pushing out slightly changed binary to all it's nodes. Kind of makes traditional AV that is signature based worthless against it. I was reading about one a month ago or so that altered it's code as it moved from machine to machine, I don't think Kraken does that from what I have thus far read. If I understand the workings of that correctly, until behavior analysis style AV becomes more popular this isn't going to be protected against.
On a related note, just started trying out Comodo firewall at home, anyone else use it? Seems kind of nifty, I've been using the free Zonealarm firewall for years. The built in registry lock seems interesting, kind of like Tea Timer from Spybot, but less buggy interface wise. I'm assuming a decent personal firewall set up correctly would be at least more helpful than AV vs a bot infection, then again there is the rootkit you probably don't find anyway heh.
Logged
"Bad.. Good? I'm the guy with the gun"
dean
Full Member
Offline
Posts: 130
Re: new botnet, largest ever
«
Reply #4 on:
April 08, 2008, 08:40:46 PM »
Dynamic binary repacking and code obfuscation and static/dynamic analysis techniques are not new. Most bots have some level of each today. Storm's binary changes approximately every 15minuts or so. I ran an analysis on about 60 binaries of Storm collected over a period of one hour and from different url's and about 30% were unique.
As for Kraken, there is talk that it may be FUD on the part of Damballa.
""We've taken a look at this and it seems the Damballa guys are into rebranding, and that they've simply taken Bobax" and presented it as Kraken, said Dmitri Alperovitch, director of intelligence analysis at Secure Computing, also based in Atlanta."
http://blog.washingtonpost.com/securityfix/2008/04/kraken_creates_a_clash_of_the.html
Some more links:
http://www.incidents.org/diary.html?storyid=4256
http://emergingthreats.net/
- includes links to other sites with in.
Either way it's interesting to note that bots and the management of them is evolving and so detection is getting more difficult at both a network and host level. Traditional methods of anti virus or anti spyware are limited and so use of honeynets and honey-clients are evolving from being research tools to valid detection and mitigation solutions.
dean
Logged
<script>alert('%52%54%46%4D')</script>
shawal
Jr. Member
Offline
Posts: 86
Re: new botnet, largest ever
«
Reply #5 on:
April 08, 2008, 11:53:54 PM »
g00d_4sh ,
firewalls do prevent from most of the threats, however they are not the key factor in preventing this. enterprise/personal firewall would still most likely allow port 80 trafic to pass. most likely you have asked the personal firewal to always trust your favourite browser. so if the bot agent/trojan/malware can inject itself onto the browser code, or even spoof itself as it is the firewall is uselss
Dean,
Interesting URLs, need to investigate this more when i have more time, and collect some storm speciemens from the wild net
Logged
RHCE, GIAC GCIH.
RoleReversal
Hero Member
Offline
Posts: 507
Re: new botnet, largest ever
«
Reply #6 on:
April 09, 2008, 04:44:27 AM »
Dean,
Quote from: dean on April 08, 2008, 08:40:46 PM
I ran an analysis on about 60 binaries of Storm collected over a period of one hour and from different url's and about 30% were unique.
Sounds like you've been having some fun, are you able/willing to tell what tools/processes your are using to collect your samples?
Logged
A little bit of sanity:
http://www.infosanity.co.uk
dean
Full Member
Offline
Posts: 130
Re: new botnet, largest ever
«
Reply #7 on:
April 09, 2008, 09:04:19 AM »
Quote
Sounds like you've been having some fun, are you able/willing to tell what tools/processes your are using to collect your samples?
I use a set of perl scripts I've written to download the binaries and compare hashes on those binaries. I also use similar scripts to perform lookups and geo-ip mapping to determine the locations of compromised machines. The urls/ip addresses come from various spam emails that I collect, honeypots like nepenthes and client honeypots like honey-hpc.
If anyone is interested I'll post some of the scripts.
dean
Logged
<script>alert('%52%54%46%4D')</script>
shawal
Jr. Member
Offline
Posts: 86
Re: new botnet, largest ever
«
Reply #8 on:
April 09, 2008, 10:51:07 AM »
Dean,
is that an XSS test in your signature?
Logged
RHCE, GIAC GCIH.
dean
Full Member
Offline
Posts: 130
Re: new botnet, largest ever
«
Reply #9 on:
April 09, 2008, 02:04:14 PM »
It could be but the sig is more of a joke.
type:
javascript:alert('%52%54%46%4D')
in your browsers navigation bar.
It will decode the hex for you.
dean
Logged
<script>alert('%52%54%46%4D')</script>
dean
Full Member
Offline
Posts: 130
Re: new botnet, largest ever
«
Reply #10 on:
April 09, 2008, 04:19:41 PM »
In follow up to the original post.
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9076278&source=NLT_PM&nlid=8
Joe Stewart presented his findings at RSA on the top botnets.
dean
Logged
<script>alert('%52%54%46%4D')</script>
RoleReversal
Hero Member
Offline
Posts: 507
Re: new botnet, largest ever
«
Reply #11 on:
April 10, 2008, 02:10:06 AM »
Dean,
Quote from: dean on April 09, 2008, 02:04:14 PM
javascript:alert('%52%54%46%4D')
nice
Thanks for the link to Keizer's article, makes for interesting reading.
One aspect that always surprises me witht these sorts of articles is the numbers of infections etc. that get quoted as fact. I might be missing a trick, but is there any more to these figures than educated guesswork? I just can't see how any of these stats could be claimed with any definity.
Logged
A little bit of sanity:
http://www.infosanity.co.uk
dean
Full Member
Offline
Posts: 130
Re: new botnet, largest ever
«
Reply #12 on:
April 10, 2008, 08:37:27 AM »
The numbers are an estimate but they can be pretty accurate. It depends on how you do the detection. Arbor Networks has a worldwide series of Honeypots in place at most of the large ISPs. This with the netflow they use for doing analysis can give a pretty good indication of the spread/scale of an infection. Have a look at
http://atlas.arbor.net/
Secureworks seem to have developed signatures for the smtp engines the bots use and detect the traffic that way using spam traps.
Trustedsouce have this page that tracks the spread of storm:
http://www.trustedsource.org/TS?do=threats&subdo=storm_tracker
For a fastflux/round robin DNS enabled botnet I use simple dns queries of a malware domain but query against multiple nameservers to determine the number of unique ip addresses associated with that domain. By running this over a period of time, until you see the rate of infection begin to decline, you can estimate the scale of the botnet.
I also sometimes run a script that will masquerade as a bot in a channel and collect information on the size of the channel. I've also seen research on P2P based botnets where the P2P network is 'crawled'.
None of this is perfect as you are dealing with changing bot code, new domains, time zones, etc... but if you trend it out over time you can get a pretty good indication of the size of the botnet.
I posted a simple lookup script in another post that will run continuous lookups on a domain and map the ip to country. It's interesting just to run it on a domain to see the results.
dean
Logged
<script>alert('%52%54%46%4D')</script>
RoleReversal
Hero Member
Offline
Posts: 507
Re: new botnet, largest ever
«
Reply #13 on:
April 10, 2008, 10:44:51 AM »
Dean,
thanks for the response and links, looks like I've got some extra research to do.
Logged
A little bit of sanity:
http://www.infosanity.co.uk
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> Certification
===> The Charter Study Group - Pen Test
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Heffner
=> Hoffman
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
Loading...
Sponsors
Polls
How many security events including conferences and training do you attend a year:
1 - 2
3 - 4
5 - 6
7+
None - But want to
None - Choose not to
Support EH-Net
Support EH-Net by
Buying all of your
Amazon items using
the search bar above.
Try CBT Nuggets Free!
Recent Forum Topics
Malware
: THe website is Evil but what to do??
(3) by
NickFnord
CEH - Certified Ethical Hacker
: Helow... help some tutorials...
(7) by
K3lV1n
CEH - Certified Ethical Hacker
: CEH is a scam
(20) by
K3lV1n
Malware
: uninstall trend mciro officescan clients
(0) by
Hack_80
Mass Media
: Daniel Suarez Interview
(9) by
blackazarro
Malware
: Security Forecast for 2009
(5) by
jason
News from the Outside World
: Is this acceptable?
(9) by
jason
Wireless
: Wireless Pen Testing Cards
(6) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Technical
(1) by
jason
Gates
: Oracle version module for metasploit
(2) by
BillV
Book Reviews
: [Article]-Mitnick - The Art Of Intrusion: Ch 1 - Hacking The Casinos For A Million Bu...
(5) by
jason
Links to cool sites.
: Free Computer Engineering Classes From Stanford
(3) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Creative
(1) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: [Article]-Scooby Doo and the Crypto Caper - Answers and Winners
(2) by
jason
News Items and General Discussion About EH-Net
: [Article]-Jan 2009 Free Giveaway Sponsor - Black Hat DC
(1) by
jason
Book Reviews
: Need a book suggestion!
(2) by
jason
News Items and General Discussion About EH-Net
: EH-Net Milestone - 2 Articles Cross 1 Million Page Views
(3) by
BillV
Other
: What kind of lab, machines you have for your security testing?
(12) by
charlottebandit
Malware
: Network Virus Problem
(9) by
RoleReversal
Wireless
: WUSB600N good usb ?
(2) by
nap191
Other
: FBI code cracking challenge
(3) by
jimbob
Calendar Of Events
: RSA 2009
(0) by
don
Forensics
: Network Forensic tools/practice/techniques
(2) by
jimbob
Malware
: Autoplay when i try to open the drive.
(4) by
jimbob
Physical Security
: Magnetic stripe card spoofing
(4) by
jimbob
Other
: Insanity?
(3) by
jason
CEH - Certified Ethical Hacker
: Any Practice Environment for learning tool for CEH?
(15) by
don
Wireless
: a petri-dish bridge
(2) by
don
CEH - Certified Ethical Hacker
: TFTP Tranfer time out
(5) by
jason
Tools
: tool to trace users
(8) by
pseud0
Malware
: Malware Challenge 2008 Analysis
(0) by
blackazarro
Programming
: Python 3.0 Released
(0) by
don
Forensics
: SANS SIFT Forensic toolkit
(1) by
don
Links to cool sites.
: Omgili Hacking - Another Search Engine dedicated to Hacking Related Forums
(2) by
RoleReversal
Tools
: Insecure.org's 2006 Top 100 Security Tools List Released
(10) by
shednik
Other
: Happy New Year!
(8) by
vijay2
CEH - Official Course Modules v6
: Community-built CEH Wiki
(2) by
yehg
Vote For EH-Net
progenic.com
binarica.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2009 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.