[26764] in resnet
Re: Zeus botnet anyone?
daemon@ATHENA.MIT.EDU (Hendricks, Jeremy)
Fri Sep 16 16:40:38 2011
Content-Language: en-US
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Message-ID: <2F56B11089DC8D49AC1DC326C351C163061E2C3469@EXCMS.msu.montana.edu>
Date: Fri, 16 Sep 2011 14:38:41 -0600
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: "Hendricks, Jeremy" <jeremy@MONTANA.EDU>
To: RESNET-L@listserv.nd.edu
In-Reply-To: <4E7382BC.1040704@bristol.ac.uk>
We just identified the Botnet as Zeus. The infection started slow and acted like a misconfiguration or equipment failure. Then it took off and the DDoS started. We've been lucky that it's only in one broadcast domain. We're brute forcing the issue for now by removing infected machines.
Identification was done through a trend of application/JSON traffic. 2 of the 20+ machines that came in for inspection were MacBook's. (Did I just hear the Mac community draw a breath, at least the ones in denial that Mac's can get nasty virus/Trojan/bot infections? Yes, I know this list is more enlightened) With the JSON itch, our desktop support specialist found an IP and separate URL that matches Zeus in the Java config files.
Myself and counterparts in central IT believe the botmaster is on campus in housing. That's the golden egg I'm really searching for.
For those that have dealt with Zeus, and knowing it's nature, do you even feel safe cleaning the OS with all the backdoor options of re-infection? Our volume and staff levels will make it difficult to force a reload of every machine that we've identified and removed from the network.
Zeustracker doesn't have our domain or IP addresses listed. The Botmaster even noticed the management server we use for port shutdowns, and spoofed the IP of that server to cause an IP conflict and try to stop us.
Charles ---> no, it doesn't act as a DHCP server. All traffic is IP spoofed with the MAC addresses the only identifier of the infected hosts. Only 5 addresses have been the destination of the DDoS. Each run uses a different protocol as well.
Jeremy Hendricks
Montana State University
AUXSVS/ResNet
406-994-1929
-----Original Message-----
From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of James J J Hooper
Sent: Friday, September 16, 2011 11:09 AM
To: RESNET-L@LISTSERV.ND.EDU
Subject: Re: Zeus botnet anyone?
On 16/09/2011 17:56, Crowe, Sheila wrote:
> Hey Everyone,
>
> Does anyone have any experience with ridding your network of this scourge?
> We believe that one of our VLANs may include a “bot master” and he’s
> killing us over there. It has taken us this long to just find out what
> the problem is. Any tips, hints, references for Voodoo docs,
> questions…all are welcome.
>
> TIA,
>
> Sheila Crowe
>
> Montana State University ResNet
We have DNS blocks on malware via various DNSRBLs. Any web traffic is redirected to a box that via the resources at:
https://zeustracker.abuse.ch/
determines if the particular 'hit' is zeus.
Clients with more than 5 HTTP GETs, or any HTTP POSTs, that match Zeus are contacted (wired) or contacted+access revoked (wireless or VPN).
-James
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________