[26766] in resnet
Re: Zeus botnet anyone?
daemon@ATHENA.MIT.EDU (Doughty, Marc)
Mon Sep 19 12:42:46 2011
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=bcaec5395f147cb1b404ad4df581
Message-ID: <CAEPWjzvf_ws7Zq0C-yhJG9SH272Q9Aw37-OBhgc+_=buRWEOsQ@mail.gmail.com>
Date: Mon, 19 Sep 2011 12:37:29 -0400
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: "Doughty, Marc" <marc_doughty@BROWN.EDU>
To: RESNET-L@listserv.nd.edu
In-Reply-To: <2F56B11089DC8D49AC1DC326C351C163061E2C3469@EXCMS.msu.montana.edu>
--bcaec5395f147cb1b404ad4df581
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable
If the 'master' is on campus, would it be wise to engage your local FBI
office and offer them a chance to glean some data from it before you pull
the plug? They might want to grab the machine and set it up behind a
honeypot or something so they can track the source of the infection on a
larger scale.
Also: "at least the ones in denial that Mac's can get nasty virus/Trojan/bo=
t
infections?"
I'm a big proponent of the 'Mac's are pretty safe' theory. The difference
between the two being that on these Macs I'll bet you can run ClamAV once
and they'll be clean, while on Windows they would each need many hours of
'cleanup' to get de-loused. Basically:
*Percent of Windows machines that get infected * Number of Windows machines
* time needed to clean each =3D bigger than cost of antivirus contract*
while
*Percent of Macs that get infected * Number of Macs * time needed to clean
each =3D smaller than cost of AV contract*
I think the math/economics of this work out to show that if you've been
paying for Mac antivirus for the last decade, you've been getting very
little return on investment compared to not paying and dealing with the
occasional cleanup. That math could change any day, but until it does, I'm
comfy recommending users to take it easy.
- Marc Doughty
"If you aren't sure who is the give-way vessel, you are the give-way
vessel."
On Fri, Sep 16, 2011 at 4:38 PM, Hendricks, Jeremy <jeremy@montana.edu>wrot=
e:
> We just identified the Botnet as Zeus. The infection started slow and
> acted like a misconfiguration or equipment failure. Then it took off and
> the DDoS started. We've been lucky that it's only in one broadcast domai=
n.
> We're brute forcing the issue for now by removing infected machines.
>
> Identification was done through a trend of application/JSON traffic. 2 o=
f
> the 20+ machines that came in for inspection were MacBook's. (Did I just
> hear the Mac community draw a breath, at least the ones in denial that
> Mac's can get nasty virus/Trojan/bot infections? Yes, I know this list i=
s
> more enlightened) With the JSON itch, our desktop support specialist fou=
nd
> an IP and separate URL that matches Zeus in the Java config files.
>
> Myself and counterparts in central IT believe the botmaster is on campus =
in
> housing. That's the golden egg I'm really searching for.
>
> For those that have dealt with Zeus, and knowing it's nature, do you even
> feel safe cleaning the OS with all the backdoor options of re-infection?
> Our volume and staff levels will make it difficult to force a reload of
> every machine that we've identified and removed from the network.
>
> Zeustracker doesn't have our domain or IP addresses listed. The Botmaste=
r
> even noticed the management server we use for port shutdowns, and spoofed
> the IP of that server to cause an IP conflict and try to stop us.
>
> Charles ---> no, it doesn't act as a DHCP server. All traffic is IP
> spoofed with the MAC addresses the only identifier of the infected hosts.
> Only 5 addresses have been the destination of the DDoS. Each run uses a
> different protocol as well.
>
>
> Jeremy Hendricks
> Montana State University
> AUXSVS/ResNet
> 406-994-1929
>
>
>
> -----Original Message-----
> From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of James J
> J Hooper
> Sent: Friday, September 16, 2011 11:09 AM
> To: RESNET-L@LISTSERV.ND.EDU
> Subject: Re: Zeus botnet anyone?
>
> On 16/09/2011 17:56, Crowe, Sheila wrote:
> > Hey Everyone,
> >
> > Does anyone have any experience with ridding your network of this
> scourge?
> > We believe that one of our VLANs may include a =93bot master=94 and he=
=92s
> > killing us over there. It has taken us this long to just find out what
> > the problem is. Any tips, hints, references for Voodoo docs,
> > questions=85all are welcome.
> >
> > TIA,
> >
> > Sheila Crowe
> >
> > Montana State University ResNet
>
> We have DNS blocks on malware via various DNSRBLs. Any web traffic is
> redirected to a box that via the resources at:
> https://zeustracker.abuse.ch/
> determines if the particular 'hit' is zeus.
>
> Clients with more than 5 HTTP GETs, or any HTTP POSTs, that match Zeus ar=
e
> contacted (wired) or contacted+access revoked (wireless or VPN).
>
> -James
>
> ___________________________________________________
> You are subscribed to the ResNet-L mailing list.
>
> To subscribe, unsubscribe or search the archives, go to
> http://LISTSERV.ND.EDU/archives/resnet-l.html
> ___________________________________________________
>
> ___________________________________________________
> You are subscribed to the ResNet-L mailing list.
>
> To subscribe, unsubscribe or search the archives,
> go to http://LISTSERV.ND.EDU/archives/resnet-l.html
> ___________________________________________________
>
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
--bcaec5395f147cb1b404ad4df581
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable
If the 'master' is on campus, would it be wise to engage your local=
FBI office and offer them a chance to glean some data from it before you p=
ull the plug? They might want to grab the machine and set it up behind a ho=
neypot or something so they can track the source of the infection on a larg=
er scale.<br>
<br>Also: "at least the ones in denial that Mac's can get nasty vi=
rus/Trojan/bot infections?"<br><br>I'm a big proponent of the '=
;Mac's are pretty safe' theory. The difference between the two bein=
g that on these Macs I'll bet you can run ClamAV once and they'll b=
e clean, while on Windows they would each need many hours of 'cleanup&#=
39; to get de-loused. Basically:<br>
<br><b>Percent of Windows machines that get infected * Number of Windows ma=
chines * time needed to clean each =3D bigger than cost of antivirus contra=
ct</b><br><br>while<br><br><b>Percent of Macs that get infected * Number of=
Macs * time needed to clean each =3D smaller than cost of AV contract</b><=
br clear=3D"all">
<br>I think the math/economics of this work out to show that if you've =
been paying for Mac antivirus for the last decade, you've been getting =
very little return on investment compared to not paying and dealing with th=
e occasional cleanup. That math could change any day, but until it does, I&=
#39;m comfy recommending users to take it easy.<br>
<br>- Marc Doughty<br>"If you aren't sure who is the give-way vess=
el, you are the give-way vessel."<br>
<br><br><div class=3D"gmail_quote">On Fri, Sep 16, 2011 at 4:38 PM, Hendric=
ks, Jeremy <span dir=3D"ltr"><<a href=3D"mailto:jeremy@montana.edu">jere=
my@montana.edu</a>></span> wrote:<br><blockquote class=3D"gmail_quote" s=
tyle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
We just identified the Botnet as Zeus. =A0The infection started slow and ac=
ted like a misconfiguration or equipment failure. =A0Then it took off and t=
he DDoS started. =A0We've been lucky that it's only in one broadcas=
t domain. =A0We're brute forcing the issue for now by removing infected=
machines.<br>
<br>
Identification was done through a trend of application/JSON traffic. =A02 o=
f the 20+ machines that came in for inspection were MacBook's. =A0(Did =
I just hear the Mac =A0community draw a breath, at least the ones in denial=
that Mac's can get nasty virus/Trojan/bot infections? =A0Yes, I know t=
his list is more enlightened) =A0With the JSON itch, our desktop support sp=
ecialist found an IP and separate URL that matches Zeus in the Java config =
files.<br>
<br>
Myself and counterparts in central IT believe the botmaster is on campus in=
housing. =A0That's the golden egg I'm really searching for.<br>
<br>
For those that have dealt with Zeus, and knowing it's nature, do you ev=
en feel safe cleaning the OS with all the backdoor options of re-infection?=
=A0Our volume and staff levels will make it difficult to force a reload of=
every machine that we've identified and removed from the network.<br>
<br>
Zeustracker doesn't have our domain or IP addresses listed. =A0The Botm=
aster even noticed the management server we use for port shutdowns, and spo=
ofed the IP of that server to cause an IP conflict and try to stop us.<br>
<br>
Charles ---> no, it doesn't act as a DHCP server. =A0All traffic is =
IP spoofed with the MAC addresses the only identifier of the infected hosts=
. =A0Only 5 addresses have been the destination of the DDoS. =A0Each run us=
es a different protocol as well.<br>
<font color=3D"#888888"><br>
<br>
Jeremy Hendricks<br>
Montana State University<br>
AUXSVS/ResNet<br>
<a href=3D"tel:406-994-1929" value=3D"+14069941929">406-994-1929</a><br>
</font><div class=3D"im"><br>
<br>
<br>
-----Original Message-----<br>
From: Resnet Forum [mailto:<a href=3D"mailto:RESNET-L@LISTSERV.ND.EDU">RESN=
ET-L@LISTSERV.ND.EDU</a>] On Behalf Of James J J Hooper<br>
Sent: Friday, September 16, 2011 11:09 AM<br>
To: <a href=3D"mailto:RESNET-L@LISTSERV.ND.EDU">RESNET-L@LISTSERV.ND.EDU</a=
><br>
Subject: Re: Zeus botnet anyone?<br>
<br>
</div><div><div></div><div class=3D"h5">On 16/09/2011 17:56, Crowe, Sheila =
wrote:<br>
> Hey Everyone,<br>
><br>
> Does anyone have any experience with ridding your network of this scou=
rge?<br>
> We believe that one of our VLANs may include a =93bot master=94 and he=
=92s<br>
> killing us over there. It has taken us this long to just find out what=
<br>
> the problem is. Any tips, hints, references for Voodoo docs,<br>
> questions=85all are welcome.<br>
><br>
> TIA,<br>
><br>
> Sheila Crowe<br>
><br>
> Montana State University ResNet<br>
<br>
We have DNS blocks on malware via various DNSRBLs. Any web traffic is redir=
ected to a box that via the resources at:<br>
<a href=3D"https://zeustracker.abuse.ch/" target=3D"_blank">https://zeustra=
cker.abuse.ch/</a><br>
determines if the particular 'hit' is zeus.<br>
<br>
Clients with more than 5 HTTP GETs, or any HTTP POSTs, that match Zeus are =
contacted (wired) or contacted+access revoked (wireless or VPN).<br>
<br>
-James<br>
<br>
___________________________________________________<br>
You are subscribed to the ResNet-L mailing list.<br>
<br>
To subscribe, unsubscribe or search the archives, go to <a href=3D"http://L=
ISTSERV.ND.EDU/archives/resnet-l.html" target=3D"_blank">http://LISTSERV.ND=
.EDU/archives/resnet-l.html</a><br>
___________________________________________________<br>
<br>
___________________________________________________<br>
You are subscribed to the ResNet-L mailing list.<br>
<br>
To subscribe, unsubscribe or search the archives,<br>
go to <a href=3D"http://LISTSERV.ND.EDU/archives/resnet-l.html" target=3D"_=
blank">http://LISTSERV.ND.EDU/archives/resnet-l.html</a><br>
___________________________________________________<br>
</div></div></blockquote></div><br>
___________________________________________________
You are subscribed to the ResNet-L mailing list.
<p>
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
--bcaec5395f147cb1b404ad4df581--