« A little more on Donbot... | Main | Smashing the Mega-d/Ozdok botnet in 24 hours »

2009.11.03

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d835018afd53ef0120a6a0fb8f970c

Listed below are links to weblogs that reference Killing the beast...Part 4 (Ozdok):

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

I wonder if Microsoft could push out kernel-level IP blocklists to stop this type of thing. I guess bots would just work around it quickly enough though.

No Geezer, not that simple because the source only need have the public half of a strong-crypto key pair; finding the private half to bring up your neutered CnC would be quite difficult assuming "high grade crypto"... difficult as in "would take millions of compute-years to crack"...meanwhile black hat can just replace the key more often than that...

Impressive but can you guys detect and remove the firmware hard drive virus that is infecting pen drives, hard drives, and cd roms. It works both in xp and linux, seems not to cause harm in windows. It is a firmware problem since the drives change disk size and leave space for gahered data.

Im quite suprised that you had GoDaddy help, they are usually blind to help combat spam and abuse, unless that is, your website is critical of a politican

Somebody with super hacking powers should prepare self-clean Ozdok "update", hack into one of CnC servers and put it there, and upload it to as many zombie PCs as possible before herders notice (and then destroy the CnC too).

That way the PCs itself will get cleaned. (I think erasing whole windows directory and MBR will kill also other possible malware, yet it will give the careless users a chance to recover their data at least)

I think that would hurt the herders a lot.
There are just 2 problems:
1) it's not legal to delete user files (although IMHO they deserve it) (and I think GOV should cooperate on this)
2) we need that super hacker hero who's capable to prepare cleaning "update" in timely fashion + get it into some CnC server.

Maybe I am missing the obvious here but since the malware keeps going looking for the cnc until it finds one, surely the best approach would be to subsitute a benign cnc.

Even if the malware uses fairly high grade cryptography, I would have thought that having a copy of the source (the malware) and some grunty server farms would be enough to crack it.

The comments to this entry are closed.

Enter your email address:

Delivered by FeedBurner

Bookmark and Share

Twitter Updates

    follow me on Twitter

    In The News