Launched a new section Breaking News Around The Globe. Did you miss any of volcanic news? Be updated before the news flashes on your news channel.
Learn How to Earn Online Money. Speak Asia Online Money Earning.

Receive Daily Updates

Enter your email address:

Saturday, April 30, 2011

The shutdown of the Coreflood botnet: Botnet Are They Really Dead or Will They Rise Again?

The shutdown of the Coreflood botnet: Botnet Are They Really Dead or Will They Rise Again?
There have been several victories against major botnets in the past few months, the most recent being the shutdown of the Coreflood botnet. Even though law enforcement officials have successfully collaborated with various industry expertsincluding Microsoft's Digital Crimes Unit and Symantecto track down and seize command-and-control servers pumping instructions to infected machines, for the most part the operators remain at large.
While the Federal Bureau of Investigation has seized control the Coreflood botnet, it is now working with Microsoft to try to permanently remove malware from thousands of infected zombie machines to prevent Coreflood from springing back to life.
Now that the Federal Bureau of Investigation has successfully disarmed the Coreflood botnet temporarily, the next step is to get the malware off infected machines.
The number of beacons, or requests from Coreflood zombies to the C&C (command and control) servers have declined by over 90 percent in the week since the FBI raided and seized five C&C servers and 29 domains used to control the Coreflood botnet, according to court documents filed April 22. The requests have dropped from about 800,000 on April 13, two days before the raid, to less than 100,000 on April 22, according to court papers.
Many users were unaware their systems had been compromised in the first place and may still be infected even though the C&C servers are offline. With these dormant machines out there, it's possible that operators can resurrect the botnet at a later time and push out updated instructions to awaken its zombie army. "It stands to reason that when we stop seeing new exploits, that the entire botnet has to be on the decline," Patrick Cummins, a security malware researcher at Blue Coat Security, told eWEEK. The success and ultimate survival of the botnet depend on being able to continuously update its zombies. The U.S. Department of Justice employed a controversial technique to ensure Coreflood can't be revived by overwriting the malicious code on compromised systems with a new set of instructions.

0 Visitor Reactions & Comments: