News: Cexx forums, with volunteers dedicated to helping you remove malware and stay protected
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
May 25, 2013, 03:28:53
Pages: 1 ... 3 4 [5]   Go Down
  Print  
Topic: Pandemic of the botnets 2009  (Read 24169 times)
0 Members and 1 Guest are viewing this topic.
« Reply #60 on: December 16, 2009, 21:04:37 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7328



FYI...

Group IDs hotbeds of Conficker worm outbreaks
- http://voices.washingtonpost.com/securityfix/2009/12/group_ids_hotbeds_of_conficker.html
December 16, 2009 - "Internet service providers in Russia and Ukraine are home to some of the highest concentrations of customers whose machines are infected with the Conficker worm, new data suggests. The report comes from the Shadowserver Foundation*, a nonprofit that tracks global botnet infections. Shadowserver tracks networks and nations most impacted by Conficker, a computer worm that has infected more than 7 million Microsoft Windows PCs since it first surfaced last November... Shadowserver's numbers indicate that the largest numbers of Conficker-infested PCs are in the East, more specifically China, India and Vietnam. For example, Chinanet, among the nation's largest ISPs, has about 92 million routable Internet addresses, and roughly 950,000 - or about 1 percent of those addresses - appear to be sickened with Conficker. Security Fix decided to use the group's data in a slightly different way, to showcase the concentration of Conficker victims as viewed against the total number of each ISP's customers. Viewed this way, Russian and Ukrainian ISPs have the highest concentration of customers with Conficker-infected systems... Shadowserver offers all ISPs and Web hosting providers free daily feeds** that can alert network providers to new bot infections on their networks."
* http://www.shadowserver.org/wiki/pmwiki.php/Stats/Conficker

** http://www.shadowserver.org/wiki/pmwiki.php/Involve/GetReportsOnYourNetwork

Conficker Eye Chart
- http://www.confickerworkinggroup.org/infection_test/cfeyechart.html

- http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091216
16 December 2009

 Exclamation
Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
« Reply #61 on: December 18, 2009, 15:28:15 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7328



FYI...

Analysis of the iKee.B (Duh) iphone Botnet
- http://www.csl.sri.com/users/porras/iPhone-Bot/
14 December 2009 - "... analysis of the iKee.B (duh) Apple iPhone bot client, captured on 25 November 2009. The bot client was released throughout several countries in Europe, with the initial purpose of stealing SMS content and coordinating its infected iPhones via a Lithuanian botnet server. This report details the logic and function of iKee's scripts, its configuration files, and its two binary executables, which we have reverse engineered to an approximation of their C source code implementation. The iKee bot is one of the latest offerings in smartphone malware, in this case targeting jailbroken iPhones. While its implementation is simple in comparison to the latest generation of PC-based malware, its implications demonstrate the potential extension of crimeware to this valuable new frontier of handheld consumer devices...
In early November 2009, Dutch users of jailbroken iPhones in T-Mobile's 3G IP range began experiencing extortion popup windows. The popup window notifies the victim that the phone has been hacked, and then sends that victim to a website where a $5 ransom payment is demanded to remove the malware infection. The teenage hacker who authored the malicious software (malware) had discovered that many jailbroken iPhones have been configured with a secure shell (SSH) network service with a known default root password..."
(Complete analysis at the URL above.)

- http://en.wikipedia.org/wiki/Jailbreak_(iPhone)

- http://www.f-secure.com/weblog/archives/00001822.html
November 22, 2009

 Shocked Evil or Very Mad Questioning or Suspicious
« Last Edit: December 18, 2009, 15:55:14 by AplusWebMaster » Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
« Reply #62 on: December 22, 2009, 04:33:13 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7328



FYI...

Citibank hacked for millions...
- http://www.pcworld.com/businesscenter/article/185271/report_russian_gang_linked_to_big_citibank_hack.html
December 21, 2009 - "U.S. authorities are investigating the theft of an estimated tens of millions of dollars from Citibank by hackers partly using Russian software tailored for the attack, according to a news report. The security breach at the major U.S. bank was detected mid-year based on traffic from Internet addresses formerly used by the Russian Business Network gang, The Wall Street Journal said Tuesday*, citing unnamed government sources. The Russian Business Network is a well-known group linked to malicious software, hacking, child pronography and spam. The Federal Bureau of Investigation is probing the case, the report said. It was not known whether the money had been recovered and a Citibank representative said the company had not had any system breach or losses, according to the report. The report left unclear who the money was stolen from but said a program called Black Energy, designed by a Russian hacker, was one tool used in the attack. The tool can be used to command a botnet, or a large group of computers infected by malware and controlled by an attacker, in assaults meant to take down target Web sites. This year a modified version of the software appeared online that could steal banking information, and in the Citi attack a version tailored to target the bank was used, the Journal said. The attackers also targeted a U.S. government agency and one other unnamed entity, the report said, adding that it was unknown if the attackers accessed Citibank systems directly or through other parties."
* http://online.wsj.com/article/SB126145280820801177.html

- http://finance.yahoo.com/news/Report-FBI-probes-hacker-apf-2149710519.html?x=0
December 22, 2009 - "... Citigroup denied the report. "We had no breach of the system and there were no losses, no customer losses, no bank losses," said Joe Petro, managing director of Citigroup's Security and Investigative services. "Any allegation that the FBI is working a case at Citigroup involving tens of millions of losses is just not true"..."

 Shocked Evil or Very Mad Evil or Very Mad
« Last Edit: December 22, 2009, 08:59:31 by AplusWebMaster » Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
 
Pages: 1 ... 3 4 [5]   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Page created in 0.134 seconds with 19 queries.