[26768] in resnet

home help back first fref pref prev next nref lref last post

Re: Zeus botnet anyone?

daemon@ATHENA.MIT.EDU (Hendricks, Jeremy)
Mon Sep 19 14:10:29 2011

Content-Language: en-US
Content-Type: multipart/alternative; boundary="_000_2F56B11089DC8D49AC1DC326C351C163061E2C3988EXCMSmsumonta_"
MIME-Version: 1.0
Message-ID:  <2F56B11089DC8D49AC1DC326C351C163061E2C3988@EXCMS.msu.montana.edu>
Date:         Mon, 19 Sep 2011 12:05:28 -0600
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: "Hendricks, Jeremy" <jeremy@MONTANA.EDU>
To: RESNET-L@listserv.nd.edu
In-Reply-To:  <CAEPWjzvf_ws7Zq0C-yhJG9SH272Q9Aw37-OBhgc+_=buRWEOsQ@mail.gmail.com>

--_000_2F56B11089DC8D49AC1DC326C351C163061E2C3988EXCMSmsumonta_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

I agree with this whole heartedly.  I'm not a forensics expert because I we=
nt to a conference in SC once years ago, and the seriousness of a Bot of th=
is kind needs specialized law enforcement.  I plan on proving the inside LA=
N/outside WAN Command & Control server today with some blacklisting of know=
n domains and IP's used and tracked.  If the Botmaster installed another C&=
C server on the LAN segment, I'll be able to identify the traffic from our =
packet captures or from the configuration files that can be read from an in=
fected machine.  If the source address spoofing is decoded and shows intern=
al, we already have a plan to involve the authorities.  I also have been ke=
eping the captures and infection lists as data.  I'm lucky to have support =
from others working the same angle trying to decipher if it's block and mit=
igate an external attack, or identify and contact for an internal investiga=
tion.

The rest, you'll not get an argument from me, considering I use a Mac as a =
personal preference for many reasons.  The trend is that a false sense of s=
ecurity is felt by some because of Apple's track record in the past.  With =
the new Intel chips, virtualization, and even software compatibility of pro=
cessor architecture have opened the doors to some vulnerabilities.  When th=
e machine came into the center after identification, the talk was that it w=
as clean because it was a Mac, and a brand new one.  JSON and java vulnerab=
ilities aside, there are other avenues for the intelligent person to hack j=
ust about anything with a network connection.

Your math, being sound, shows known conclusions in today's environment.  I =
agree tomorrow might be totally different.  Yesterday my flip phone was ama=
zing, today my smartphone is a business wonder that is more than I need.  T=
ablet technology, concepts like Microsoft's tables for restaurants, TV's th=
at integrate multiple network devices, are taxing support personnel harder =
than ever as the whirlwind speeds up.  I never worried when I was on my Com=
modore Vic 20, or the Kaypro10 for "mobility".  When viruses that played ya=
nkee doodle dandy on a certain day, it was funny.  I don't think anyone in =
IT back in those days thought that was going to be the scale, and knew it w=
as going to get worse.  As Mac sales increase, and compatibility with windo=
ws services are more integrated, we'll start seeing even more from that pla=
tform.  Soon enough, attacks will be as platform specific and abundant as A=
ndroid vs. Blackberry infections.  PC vs. Mac is always going to be dispute=
d, no matter the level of tech.

Now they have a bios virus variant that re-infects machines on rebooting.  =
Spyeye/Zeus bots have joined into a hybrid, adding encryption to some confi=
guration files to make tracking harder.  Even if you can track everything d=
own, there are backdoors installed that aren't taken care of in standard cl=
eaning practices.  My antivirus suite doesn't have a "nuke from orbit" butt=
on I'd love as a feature.  We all do everything we can to protect our users=
, even from themselves, spending budget money we need for other projects on=
 higher security and a better posture of logging access to identify issues =
as quickly as possible and removing them.

The statement of this group being more enlightened was left from the quoted=
 text.  It's the general Mac community that has been lulled into a false se=
nse of security.  An infected Mac, once on the network, gives access to mal=
icious people looking to grow their zombies.  Cost of cleaning in that case=
? 1 Mac allows access for the Botmaster to infect 40 vulnerable machines.  =
1 Mac just cost a lot of support and trouble because the user believed they=
 are safe and don't need to be scanning for compromises as Windows users ha=
ve been taught over the years.

An ounce of education saves a lot of trouble.  I learn every day to stay ed=
ucated with the trends, which are changing faster than my hair color.  WEP =
40bit is fine encryption for any wireless right??? Hasn't been long since t=
hat statement was believed truth.

  https://blog.trendmicro.com/full-analysis-of-the-zeus-licat-trojan/  <-- =
good information from trend micro for those interested in what things are g=
etting like in the Bot world, and the column on the right has information o=
n the new hybrid Bots.


Jeremy Hendricks
Montana State University
AUXSVS/ResNet
406-994-1929

"Proactive or reactive, the issue will have to be addressed.  The differenc=
e is the Pucker Factor" - anon


From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of Doughty, =
Marc
Sent: Monday, September 19, 2011 10:37 AM
To: RESNET-L@LISTSERV.ND.EDU
Subject: Re: Zeus botnet anyone?

If the 'master' is on campus, would it be wise to engage your local FBI off=
ice and offer them a chance to glean some data from it before you pull the =
plug? They might want to grab the machine and set it up behind a honeypot o=
r something so they can track the source of the infection on a larger scale=
.

Also: "at least the ones in denial that Mac's can get nasty virus/Trojan/bo=
t infections?"

I'm a big proponent of the 'Mac's are pretty safe' theory. The difference b=
etween the two being that on these Macs I'll bet you can run ClamAV once an=
d they'll be clean, while on Windows they would each need many hours of 'cl=
eanup' to get de-loused. Basically:

Percent of Windows machines that get infected * Number of Windows machines =
* time needed to clean each =3D bigger than cost of antivirus contract

while

Percent of Macs that get infected * Number of Macs * time needed to clean e=
ach =3D smaller than cost of AV contract

I think the math/economics of this work out to show that if you've been pay=
ing for Mac antivirus for the last decade, you've been getting very little =
return on investment compared to not paying and dealing with the occasional=
 cleanup. That math could change any day, but until it does, I'm comfy reco=
mmending users to take it easy.

- Marc Doughty
"If you aren't sure who is the give-way vessel, you are the give-way vessel=
."

On Fri, Sep 16, 2011 at 4:38 PM, Hendricks, Jeremy <jeremy@montana.edu<mail=
to:jeremy@montana.edu>> wrote:
We just identified the Botnet as Zeus.  The infection started slow and acte=
d like a misconfiguration or equipment failure.  Then it took off and the D=
DoS started.  We've been lucky that it's only in one broadcast domain.  We'=
re brute forcing the issue for now by removing infected machines.

Identification was done through a trend of application/JSON traffic.  2 of =
the 20+ machines that came in for inspection were MacBook's.  (Did I just h=
ear the Mac  community draw a breath, at least the ones in denial that Mac'=
s can get nasty virus/Trojan/bot infections?  Yes, I know this list is more=
 enlightened)  With the JSON itch, our desktop support specialist found an =
IP and separate URL that matches Zeus in the Java config files.

Myself and counterparts in central IT believe the botmaster is on campus in=
 housing.  That's the golden egg I'm really searching for.

For those that have dealt with Zeus, and knowing it's nature, do you even f=
eel safe cleaning the OS with all the backdoor options of re-infection?  Ou=
r volume and staff levels will make it difficult to force a reload of every=
 machine that we've identified and removed from the network.

Zeustracker doesn't have our domain or IP addresses listed.  The Botmaster =
even noticed the management server we use for port shutdowns, and spoofed t=
he IP of that server to cause an IP conflict and try to stop us.

Charles ---> no, it doesn't act as a DHCP server.  All traffic is IP spoofe=
d with the MAC addresses the only identifier of the infected hosts.  Only 5=
 addresses have been the destination of the DDoS.  Each run uses a differen=
t protocol as well.


Jeremy Hendricks
Montana State University
AUXSVS/ResNet
406-994-1929<tel:406-994-1929>



-----Original Message-----
From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU<mailto:RESNET-L@LISTSER=
V.ND.EDU>] On Behalf Of James J J Hooper
Sent: Friday, September 16, 2011 11:09 AM
To: RESNET-L@LISTSERV.ND.EDU<mailto:RESNET-L@LISTSERV.ND.EDU>
Subject: Re: Zeus botnet anyone?
On 16/09/2011 17:56, Crowe, Sheila wrote:
> Hey Everyone,
>
> Does anyone have any experience with ridding your network of this scourge=
?
> We believe that one of our VLANs may include a "bot master" and he's
> killing us over there. It has taken us this long to just find out what
> the problem is. Any tips, hints, references for Voodoo docs,
> questions...all are welcome.
>
> TIA,
>
> Sheila Crowe
>
> Montana State University ResNet

We have DNS blocks on malware via various DNSRBLs. Any web traffic is redir=
ected to a box that via the resources at:
https://zeustracker.abuse.ch/
determines if the particular 'hit' is zeus.

Clients with more than 5 HTTP GETs, or any HTTP POSTs, that match Zeus are =
contacted (wired) or contacted+access revoked (wireless or VPN).

-James

___________________________________________________
You are subscribed to the ResNet-L mailing list.

To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html
___________________________________________________

___________________________________________________
You are subscribed to the ResNet-L mailing list.

To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

___________________________________________________ You are subscribed to t=
he ResNet-L mailing list.

To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html ________________________________________________=
___

___________________________________________________
You are subscribed to the ResNet-L mailing list.

To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

--_000_2F56B11089DC8D49AC1DC326C351C163061E2C3988EXCMSmsumonta_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40"><head><meta http-equiv=3DContent-Type content=
=3D"text/html; charset=3Diso-8859-1"><meta name=3DGenerator content=3D"Micr=
osoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue vli=
nk=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span style=3D'f=
ont-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>I agree w=
ith this whole heartedly.=A0 I&#8217;m not a forensics expert because I wen=
t to a conference in SC once years ago, and the seriousness of a Bot of thi=
s kind needs specialized law enforcement.=A0 I plan on proving the inside L=
AN/outside WAN Command &amp; Control server today with some blacklisting of=
 known domains and IP&#8217;s used and tracked.=A0 If the Botmaster install=
ed another C&amp;C server on the LAN segment, I&#8217;ll be able to identif=
y the traffic from our packet captures or from the configuration files that=
 can be read from an infected machine.=A0 If the source address spoofing is=
 decoded and shows internal, we already have a plan to involve the authorit=
ies.=A0 I also have been keeping the captures and infection lists as data.=
=A0 I&#8217;m lucky to have support from others working the same angle tryi=
ng to decipher if it&#8217;s block and mitigate an external attack, or iden=
tify and contact for an internal investigation.=A0 <o:p></o:p></span></p><p=
 class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","s=
ans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal>=
<span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1=
F497D'>The rest, you&#8217;ll not get an argument from me, considering I us=
e a Mac as a personal preference for many reasons.=A0 The trend is that a f=
alse sense of security is felt by some because of Apple&#8217;s track recor=
d in the past.=A0 With the new Intel chips, virtualization, and even softwa=
re compatibility of processor architecture have opened the doors to some vu=
lnerabilities.=A0 When the machine came into the center after identificatio=
n, the talk was that it was clean because it was a Mac, and a brand new one=
.=A0 JSON and java vulnerabilities aside, there are other avenues for the i=
ntelligent person to hack just about anything with a network connection. <o=
:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;fo=
nt-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p=
><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri"=
,"sans-serif";color:#1F497D'> Your math, being sound, shows known conclusio=
ns in today&#8217;s environment.=A0 I agree tomorrow might be totally diffe=
rent.=A0 Yesterday my flip phone was amazing, today my smartphone is a busi=
ness wonder that is more than I need.=A0 Tablet technology, concepts like M=
icrosoft&#8217;s tables for restaurants, TV&#8217;s that integrate multiple=
 network devices, are taxing support personnel harder than ever as the whir=
lwind speeds up.=A0 I never worried when I was on my Commodore Vic 20, or t=
he Kaypro10 for &#8220;mobility&#8221;.=A0 When viruses that played yankee =
doodle dandy on a certain day, it was funny.=A0 I don&#8217;t think anyone =
in IT back in those days thought that was going to be the scale, and knew i=
t was going to get worse.=A0 As Mac sales increase, and compatibility with =
windows services are more integrated, we&#8217;ll start seeing even more fr=
om that platform. =A0Soon enough, attacks will be as platform specific and =
abundant as Android vs. Blackberry infections.=A0 PC vs. Mac is always goin=
g to be disputed, no matter the level of tech.<o:p></o:p></span></p><p clas=
s=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-s=
erif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span=
 style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D=
'>Now they have a bios virus variant that re-infects machines on rebooting.=
=A0 Spyeye/Zeus bots have joined into a hybrid, adding encryption to some c=
onfiguration files to make tracking harder.=A0 Even if you can track everyt=
hing down, there are backdoors installed that aren&#8217;t taken care of in=
 standard cleaning practices.=A0 My antivirus suite doesn&#8217;t have a &#=
8220;nuke from orbit&#8221; button I&#8217;d love as a feature.=A0 We all d=
o everything we can to protect our users, even from themselves, spending bu=
dget money we need for other projects on higher security and a better postu=
re of logging access to identify issues as quickly as possible and removing=
 them.=A0 <o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-si=
ze:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:=
p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-fami=
ly:"Calibri","sans-serif";color:#1F497D'>The statement of this group being =
more enlightened was left from the quoted text.=A0 It&#8217;s the general M=
ac community that has been lulled into a false sense of security.=A0 An inf=
ected Mac, once on the network, gives access to malicious people looking to=
 grow their zombies.=A0 Cost of cleaning in that case? 1 Mac allows access =
for the Botmaster to infect 40 vulnerable machines.=A0 1 Mac just cost a lo=
t of support and trouble because the user believed they are safe and don&#8=
217;t need to be scanning for compromises as Windows users have been taught=
 over the years.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'f=
ont-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbs=
p;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;fon=
t-family:"Calibri","sans-serif";color:#1F497D'>An ounce of education saves =
a lot of trouble.=A0 I learn every day to stay educated with the trends, wh=
ich are changing faster than my hair color.=A0 WEP 40bit is fine encryption=
 for any wireless right??? Hasn&#8217;t been long since that statement was =
believed truth.=A0 <o:p></o:p></span></p><p class=3DMsoNormal><span style=
=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p=
>&nbsp;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0p=
t;font-family:"Calibri","sans-serif";color:#1F497D'> =A0=A0<a href=3D"https=
://blog.trendmicro.com/full-analysis-of-the-zeus-licat-trojan/">https://blo=
g.trendmicro.com/full-analysis-of-the-zeus-licat-trojan/</a>=A0 </span><spa=
n style=3D'font-size:11.0pt;font-family:Wingdings;color:#1F497D'>=DF</span>=
<span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1=
F497D'> good information from trend micro for those interested in what thin=
gs are getting like in the Bot world, and the column on the right has infor=
mation on the new hybrid Bots.=A0 <o:p></o:p></span></p><p class=3DMsoNorma=
l><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:=
#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span style=3D'fo=
nt-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp=
;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font=
-family:"Calibri","sans-serif";color:#1F497D'>Jeremy Hendricks<o:p></o:p></=
span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"=
Calibri","sans-serif";color:#1F497D'>Montana State University<o:p></o:p></s=
pan></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"C=
alibri","sans-serif";color:#1F497D'>AUXSVS/ResNet<o:p></o:p></span></p><p c=
lass=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","san=
s-serif";color:#1F497D'>406-994-1929<o:p></o:p></span></p><p class=3DMsoNor=
mal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";colo=
r:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span style=3D'=
font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>&#8220;P=
roactive or reactive, the issue will have to be addressed.=A0 The differenc=
e is the Pucker Factor&#8221; - anon<o:p></o:p></span></p><p class=3DMsoNor=
mal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";colo=
r:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span style=3D'=
font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nb=
sp;</o:p></span></p><p class=3DMsoNormal><b><span style=3D'font-size:10.0pt=
;font-family:"Tahoma","sans-serif"'>From:</span></b><span style=3D'font-siz=
e:10.0pt;font-family:"Tahoma","sans-serif"'> Resnet Forum [mailto:RESNET-L@=
LISTSERV.ND.EDU] <b>On Behalf Of </b>Doughty, Marc<br><b>Sent:</b> Monday, =
September 19, 2011 10:37 AM<br><b>To:</b> RESNET-L@LISTSERV.ND.EDU<br><b>Su=
bject:</b> Re: Zeus botnet anyone?<o:p></o:p></span></p><p class=3DMsoNorma=
l><o:p>&nbsp;</o:p></p><p class=3DMsoNormal style=3D'margin-bottom:12.0pt'>=
If the 'master' is on campus, would it be wise to engage your local FBI off=
ice and offer them a chance to glean some data from it before you pull the =
plug? They might want to grab the machine and set it up behind a honeypot o=
r something so they can track the source of the infection on a larger scale=
.<br><br>Also: &quot;at least the ones in denial that Mac's can get nasty v=
irus/Trojan/bot infections?&quot;<br><br>I'm a big proponent of the 'Mac's =
are pretty safe' theory. The difference between the two being that on these=
 Macs I'll bet you can run ClamAV once and they'll be clean, while on Windo=
ws they would each need many hours of 'cleanup' to get de-loused. Basically=
:<br><br><b>Percent of Windows machines that get infected * Number of Windo=
ws machines * time needed to clean each =3D bigger than cost of antivirus c=
ontract</b><br><br>while<br><br><b>Percent of Macs that get infected * Numb=
er of Macs * time needed to clean each =3D smaller than cost of AV contract=
</b><br clear=3Dall><br>I think the math/economics of this work out to show=
 that if you've been paying for Mac antivirus for the last decade, you've b=
een getting very little return on investment compared to not paying and dea=
ling with the occasional cleanup. That math could change any day, but until=
 it does, I'm comfy recommending users to take it easy.<br><br>- Marc Dough=
ty<br>&quot;If you aren't sure who is the give-way vessel, you are the give=
-way vessel.&quot;<br><br><o:p></o:p></p><div><p class=3DMsoNormal>On Fri, =
Sep 16, 2011 at 4:38 PM, Hendricks, Jeremy &lt;<a href=3D"mailto:jeremy@mon=
tana.edu">jeremy@montana.edu</a>&gt; wrote:<o:p></o:p></p><p class=3DMsoNor=
mal>We just identified the Botnet as Zeus. &nbsp;The infection started slow=
 and acted like a misconfiguration or equipment failure. &nbsp;Then it took=
 off and the DDoS started. &nbsp;We've been lucky that it's only in one bro=
adcast domain. &nbsp;We're brute forcing the issue for now by removing infe=
cted machines.<br><br>Identification was done through a trend of applicatio=
n/JSON traffic. &nbsp;2 of the 20+ machines that came in for inspection wer=
e MacBook's. &nbsp;(Did I just hear the Mac &nbsp;community draw a breath, =
at least the ones in denial that Mac's can get nasty virus/Trojan/bot infec=
tions? &nbsp;Yes, I know this list is more enlightened) &nbsp;With the JSON=
 itch, our desktop support specialist found an IP and separate URL that mat=
ches Zeus in the Java config files.<br><br>Myself and counterparts in centr=
al IT believe the botmaster is on campus in housing. &nbsp;That's the golde=
n egg I'm really searching for.<br><br>For those that have dealt with Zeus,=
 and knowing it's nature, do you even feel safe cleaning the OS with all th=
e backdoor options of re-infection? &nbsp;Our volume and staff levels will =
make it difficult to force a reload of every machine that we've identified =
and removed from the network.<br><br>Zeustracker doesn't have our domain or=
 IP addresses listed. &nbsp;The Botmaster even noticed the management serve=
r we use for port shutdowns, and spoofed the IP of that server to cause an =
IP conflict and try to stop us.<br><br>Charles ---&gt; no, it doesn't act a=
s a DHCP server. &nbsp;All traffic is IP spoofed with the MAC addresses the=
 only identifier of the infected hosts. &nbsp;Only 5 addresses have been th=
e destination of the DDoS. &nbsp;Each run uses a different protocol as well=
.<br><span style=3D'color:#888888'><br><br>Jeremy Hendricks<br>Montana Stat=
e University<br>AUXSVS/ResNet<br><a href=3D"tel:406-994-1929">406-994-1929<=
/a></span><o:p></o:p></p><div><p class=3DMsoNormal style=3D'margin-bottom:1=
2.0pt'><br><br><br>-----Original Message-----<br>From: Resnet Forum [mailto=
:<a href=3D"mailto:RESNET-L@LISTSERV.ND.EDU">RESNET-L@LISTSERV.ND.EDU</a>] =
On Behalf Of James J J Hooper<br>Sent: Friday, September 16, 2011 11:09 AM<=
br>To: <a href=3D"mailto:RESNET-L@LISTSERV.ND.EDU">RESNET-L@LISTSERV.ND.EDU=
</a><br>Subject: Re: Zeus botnet anyone?<o:p></o:p></p></div><div><div><p c=
lass=3DMsoNormal>On 16/09/2011 17:56, Crowe, Sheila wrote:<br>&gt; Hey Ever=
yone,<br>&gt;<br>&gt; Does anyone have any experience with ridding your net=
work of this scourge?<br>&gt; We believe that one of our VLANs may include =
a &#8220;bot master&#8221; and he&#8217;s<br>&gt; killing us over there. It=
 has taken us this long to just find out what<br>&gt; the problem is. Any t=
ips, hints, references for Voodoo docs,<br>&gt; questions&#8230;all are wel=
come.<br>&gt;<br>&gt; TIA,<br>&gt;<br>&gt; Sheila Crowe<br>&gt;<br>&gt; Mon=
tana State University ResNet<br><br>We have DNS blocks on malware via vario=
us DNSRBLs. Any web traffic is redirected to a box that via the resources a=
t:<br><a href=3D"https://zeustracker.abuse.ch/" target=3D"_blank">https://z=
eustracker.abuse.ch/</a><br>determines if the particular 'hit' is zeus.<br>=
<br>Clients with more than 5 HTTP GETs, or any HTTP POSTs, that match Zeus =
are contacted (wired) or contacted+access revoked (wireless or VPN).<br><br=
>-James<br><br>___________________________________________________<br>You a=
re subscribed to the ResNet-L mailing list.<br><br>To subscribe, unsubscrib=
e or search the archives, go to <a href=3D"http://LISTSERV.ND.EDU/archives/=
resnet-l.html" target=3D"_blank">http://LISTSERV.ND.EDU/archives/resnet-l.h=
tml</a><br>___________________________________________________<br><br>_____=
______________________________________________<br>You are subscribed to the=
 ResNet-L mailing list.<br><br>To subscribe, unsubscribe or search the arch=
ives,<br>go to <a href=3D"http://LISTSERV.ND.EDU/archives/resnet-l.html" ta=
rget=3D"_blank">http://LISTSERV.ND.EDU/archives/resnet-l.html</a><br>______=
_____________________________________________<o:p></o:p></p></div></div></d=
iv><p class=3DMsoNormal><br>_______________________________________________=
____ You are subscribed to the ResNet-L mailing list. <o:p></o:p></p><p>To =
subscribe, unsubscribe or search the archives, go to <a href=3D"http://LIST=
SERV.ND.EDU/archives/resnet-l.html">http://LISTSERV.ND.EDU/archives/resnet-=
l.html</a> ___________________________________________________ <o:p></o:p><=
/p></div></body></html>=
___________________________________________________
You are subscribed to the ResNet-L mailing list.
<p>
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

--_000_2F56B11089DC8D49AC1DC326C351C163061E2C3988EXCMSmsumonta_--

home help back first fref pref prev next nref lref last post