<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » kneber</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/kneber/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Thu, 02 Sep 2010 11:22:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Kneber for sale or rent (rooms to let 50 cents)*</title>
		<link>http://countermeasures.trendmicro.eu/kneber-for-sale-or-rent-rooms-to-let-50-cents/</link>
		<comments>http://countermeasures.trendmicro.eu/kneber-for-sale-or-rent-rooms-to-let-50-cents/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 13:15:58 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[kneber]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1790</guid>
		<description><![CDATA[I realise I might be getting a reputation as the infosec curmudgeon, always ready with a bucket of cold water when the occasion demands, but once again I feel moved to write about hype. &#8220;Seemingly there is no reason for these extraordinary intergalactical upsets. Only Dr Hans Zarkov formerly at NASA has provided any explanation&#8221;* [...]]]></description>
			<content:encoded><![CDATA[<p>I realise I might be getting a reputation as the infosec curmudgeon, always ready with a <a title="Google, China, Chicken Little and Cyber Armageddon"  href="http://countermeasures.trendmicro.eu/google-china-chicken-little-and-cyber-armageddon/" target="_blank">bucket of cold water</a> when the occasion demands, but once again I feel moved to write about hype.</p>
<blockquote><p>&#8220;Seemingly there is no reason for these extraordinary intergalactical upsets. Only Dr Hans Zarkov formerly at NASA has provided any explanation&#8221;*</p></blockquote>
<p>Stories in the press recently have been aghast at the scale of a &#8220;new&#8221; botnet called Kneber. According to a <a title="NetWitness blog" href="http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/" target="-blank">report from NetWitness</a> one particular botnet that uses the ZeuS crimeware has successfully infiltrated thousands of corporations and tens of thousands of computers. This is of course terrible news for the companies affected and certainly many corporate security lessons can be learned from experiences such as this.</p>
<p>&nbsp;</p>
<p>What is important to point out though is that there is nothing at all that is &#8220;new&#8221; or &#8220;unprecedented&#8221; about a botnet using ZeuS or a botnet of this size, <a href="http://threatinfo.trendmicro.com/vinfo/web_attacks/ZeuS_ZBOTandKneberConnection.html" target="_blank">ZeuS (or ZBot)</a> has been around since at least 2007. In the online underground ZeuS is the equivalent of commodity crimeware. It is openly traded in online forums both as a software product and as preinfected botnets. Increasingly providers are finding that they must bundle services with their criminal offering,Â or Crimeware as a Service.</p>
<p>&nbsp;</p>
<div id="attachment_1792" class="wp-caption alignleft" style="width: 621px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/saleorrent.gif"><img class="size-full wp-image-1792" title="Screen shot from underground forum" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/saleorrent.gif" alt="Screen shot from underground forum" width="510" height="333" /></a><p class="wp-caption-text">Screen shot from underground forum</p></div><br />
&nbsp;</p>
<p>Older versions of the software are downloadable free of charge, though these are often backdoored by other criminals. There is no honour among thieves. In fact botnets are in such plentiful supply that the price of preinfected machines is surprisingly low.<br />
&nbsp;</p>
<p><div id="attachment_1793" class="wp-caption alignleft" style="width: 248px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/botsale.gif"><img class="size-full wp-image-1793 " title="Screen shot from underground forum" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/botsale.gif" alt="Screen shot from underground forum" width="238" height="199" /></a><p class="wp-caption-text">175 thousand bots for sale... globally.</p></div>
<p>&nbsp;</p>
<p>Of course if you don&#8217;t have the means or the desire to run your own botnet, you can always simply buy the output&#8230;</p>
<p>&nbsp;</p>
<div id="attachment_1795" class="wp-caption alignleft" style="width: 502px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/zeuslogs2.gif"><img class="size-full wp-image-1795" title="Screen shot from underground forum" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/zeuslogs2.gif" alt="https://zeustracker.abuse.ch/index.php" width="492" height="253" /></a><p class="wp-caption-text">I&#39;m a lumberjack and I&#39;m OK. Logs for sale.</p></div>
<p>&nbsp;</p>
<p>A quick look at <a title="abuse.ch ZeuS Tracker" href="https://zeustracker.abuse.ch/index.php" target="_blank">ZeuS Tracker </a>shows they are tracking almost 1300 command &amp; control servers for various ZeuS botnets of which about half are online right now. They show the average binary detection rate (how your antivirus products detects using pattern files or signatures) is as low as 49.62% which goes some way towards explaining the successful infection rate.<br />
&nbsp;<br />
It is widely known that malware writers and other criminals have already worked out how to overcome traditional anti-malware protection that relies on pattern or signature updates. They simply roll their code as often as possible, estimates say that we are currently seeing a unique malicious binary every 1.5 seconds.<br />
&nbsp;<br />
So here&#8217;s corporate security lesson number one from this recent publicity&#8230;<br />
&nbsp;<br />
Make sure your anti-malware solution is not relying simply on the infection layer &#8220;<em>what the file looks like</em>&#8220;; make sure that it is also investigating the exposure layer, &#8220;where <em>the file comes from and who the file reports back to</em>&#8220;. If ZeuS Tracker knows where the bad guy servers are, so should every one of your endpoints. At that point, what the actual binary looks like becomes a secondary issue.</p>
<p>&nbsp;<br />
By the way <a href="http://free.antivirus.com/rubotted/">here </a>is a free tool to check if you are a part of a bot network.<br />
&nbsp;<br />
* With apologies to Roger Miller and Queen</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/kneber-for-sale-or-rent-rooms-to-let-50-cents/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
