[26768] in resnet
Re: Zeus botnet anyone?
daemon@ATHENA.MIT.EDU (Hendricks, Jeremy)
Mon Sep 19 14:10:29 2011
Content-Language: en-US
Content-Type: multipart/alternative; boundary="_000_2F56B11089DC8D49AC1DC326C351C163061E2C3988EXCMSmsumonta_"
MIME-Version: 1.0
Message-ID: <2F56B11089DC8D49AC1DC326C351C163061E2C3988@EXCMS.msu.montana.edu>
Date: Mon, 19 Sep 2011 12:05:28 -0600
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: "Hendricks, Jeremy" <jeremy@MONTANA.EDU>
To: RESNET-L@listserv.nd.edu
In-Reply-To: <CAEPWjzvf_ws7Zq0C-yhJG9SH272Q9Aw37-OBhgc+_=buRWEOsQ@mail.gmail.com>
--_000_2F56B11089DC8D49AC1DC326C351C163061E2C3988EXCMSmsumonta_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
I agree with this whole heartedly. I'm not a forensics expert because I we=
nt to a conference in SC once years ago, and the seriousness of a Bot of th=
is kind needs specialized law enforcement. I plan on proving the inside LA=
N/outside WAN Command & Control server today with some blacklisting of know=
n domains and IP's used and tracked. If the Botmaster installed another C&=
C server on the LAN segment, I'll be able to identify the traffic from our =
packet captures or from the configuration files that can be read from an in=
fected machine. If the source address spoofing is decoded and shows intern=
al, we already have a plan to involve the authorities. I also have been ke=
eping the captures and infection lists as data. I'm lucky to have support =
from others working the same angle trying to decipher if it's block and mit=
igate an external attack, or identify and contact for an internal investiga=
tion.
The rest, you'll not get an argument from me, considering I use a Mac as a =
personal preference for many reasons. The trend is that a false sense of s=
ecurity is felt by some because of Apple's track record in the past. With =
the new Intel chips, virtualization, and even software compatibility of pro=
cessor architecture have opened the doors to some vulnerabilities. When th=
e machine came into the center after identification, the talk was that it w=
as clean because it was a Mac, and a brand new one. JSON and java vulnerab=
ilities aside, there are other avenues for the intelligent person to hack j=
ust about anything with a network connection.
Your math, being sound, shows known conclusions in today's environment. I =
agree tomorrow might be totally different. Yesterday my flip phone was ama=
zing, today my smartphone is a business wonder that is more than I need. T=
ablet technology, concepts like Microsoft's tables for restaurants, TV's th=
at integrate multiple network devices, are taxing support personnel harder =
than ever as the whirlwind speeds up. I never worried when I was on my Com=
modore Vic 20, or the Kaypro10 for "mobility". When viruses that played ya=
nkee doodle dandy on a certain day, it was funny. I don't think anyone in =
IT back in those days thought that was going to be the scale, and knew it w=
as going to get worse. As Mac sales increase, and compatibility with windo=
ws services are more integrated, we'll start seeing even more from that pla=
tform. Soon enough, attacks will be as platform specific and abundant as A=
ndroid vs. Blackberry infections. PC vs. Mac is always going to be dispute=
d, no matter the level of tech.
Now they have a bios virus variant that re-infects machines on rebooting. =
Spyeye/Zeus bots have joined into a hybrid, adding encryption to some confi=
guration files to make tracking harder. Even if you can track everything d=
own, there are backdoors installed that aren't taken care of in standard cl=
eaning practices. My antivirus suite doesn't have a "nuke from orbit" butt=
on I'd love as a feature. We all do everything we can to protect our users=
, even from themselves, spending budget money we need for other projects on=
higher security and a better posture of logging access to identify issues =
as quickly as possible and removing them.
The statement of this group being more enlightened was left from the quoted=
text. It's the general Mac community that has been lulled into a false se=
nse of security. An infected Mac, once on the network, gives access to mal=
icious people looking to grow their zombies. Cost of cleaning in that case=
? 1 Mac allows access for the Botmaster to infect 40 vulnerable machines. =
1 Mac just cost a lot of support and trouble because the user believed they=
are safe and don't need to be scanning for compromises as Windows users ha=
ve been taught over the years.
An ounce of education saves a lot of trouble. I learn every day to stay ed=
ucated with the trends, which are changing faster than my hair color. WEP =
40bit is fine encryption for any wireless right??? Hasn't been long since t=
hat statement was believed truth.
https://blog.trendmicro.com/full-analysis-of-the-zeus-licat-trojan/ <-- =
good information from trend micro for those interested in what things are g=
etting like in the Bot world, and the column on the right has information o=
n the new hybrid Bots.
Jeremy Hendricks
Montana State University
AUXSVS/ResNet
406-994-1929
"Proactive or reactive, the issue will have to be addressed. The differenc=
e is the Pucker Factor" - anon
From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of Doughty, =
Marc
Sent: Monday, September 19, 2011 10:37 AM
To: RESNET-L@LISTSERV.ND.EDU
Subject: Re: Zeus botnet anyone?
If the 'master' is on campus, would it be wise to engage your local FBI off=
ice and offer them a chance to glean some data from it before you pull the =
plug? They might want to grab the machine and set it up behind a honeypot o=
r something so they can track the source of the infection on a larger scale=
.
Also: "at least the ones in denial that Mac's can get nasty virus/Trojan/bo=
t infections?"
I'm a big proponent of the 'Mac's are pretty safe' theory. The difference b=
etween the two being that on these Macs I'll bet you can run ClamAV once an=
d they'll be clean, while on Windows they would each need many hours of 'cl=
eanup' to get de-loused. Basically:
Percent of Windows machines that get infected * Number of Windows machines =
* time needed to clean each =3D bigger than cost of antivirus contract
while
Percent of Macs that get infected * Number of Macs * time needed to clean e=
ach =3D smaller than cost of AV contract
I think the math/economics of this work out to show that if you've been pay=
ing for Mac antivirus for the last decade, you've been getting very little =
return on investment compared to not paying and dealing with the occasional=
cleanup. That math could change any day, but until it does, I'm comfy reco=
mmending users to take it easy.
- Marc Doughty
"If you aren't sure who is the give-way vessel, you are the give-way vessel=
."
On Fri, Sep 16, 2011 at 4:38 PM, Hendricks, Jeremy <jeremy@montana.edu<mail=
to:jeremy@montana.edu>> wrote:
We just identified the Botnet as Zeus. The infection started slow and acte=
d like a misconfiguration or equipment failure. Then it took off and the D=
DoS started. We've been lucky that it's only in one broadcast domain. We'=
re brute forcing the issue for now by removing infected machines.
Identification was done through a trend of application/JSON traffic. 2 of =
the 20+ machines that came in for inspection were MacBook's. (Did I just h=
ear the Mac community draw a breath, at least the ones in denial that Mac'=
s can get nasty virus/Trojan/bot infections? Yes, I know this list is more=
enlightened) With the JSON itch, our desktop support specialist found an =
IP and separate URL that matches Zeus in the Java config files.
Myself and counterparts in central IT believe the botmaster is on campus in=
housing. That's the golden egg I'm really searching for.
For those that have dealt with Zeus, and knowing it's nature, do you even f=
eel safe cleaning the OS with all the backdoor options of re-infection? Ou=
r volume and staff levels will make it difficult to force a reload of every=
machine that we've identified and removed from the network.
Zeustracker doesn't have our domain or IP addresses listed. The Botmaster =
even noticed the management server we use for port shutdowns, and spoofed t=
he IP of that server to cause an IP conflict and try to stop us.
Charles ---> no, it doesn't act as a DHCP server. All traffic is IP spoofe=
d with the MAC addresses the only identifier of the infected hosts. Only 5=
addresses have been the destination of the DDoS. Each run uses a differen=
t protocol as well.
Jeremy Hendricks
Montana State University
AUXSVS/ResNet
406-994-1929<tel:406-994-1929>
-----Original Message-----
From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU<mailto:RESNET-L@LISTSER=
V.ND.EDU>] On Behalf Of James J J Hooper
Sent: Friday, September 16, 2011 11:09 AM
To: RESNET-L@LISTSERV.ND.EDU<mailto:RESNET-L@LISTSERV.ND.EDU>
Subject: Re: Zeus botnet anyone?
On 16/09/2011 17:56, Crowe, Sheila wrote:
> Hey Everyone,
>
> Does anyone have any experience with ridding your network of this scourge=
?
> We believe that one of our VLANs may include a "bot master" and he's
> killing us over there. It has taken us this long to just find out what
> the problem is. Any tips, hints, references for Voodoo docs,
> questions...all are welcome.
>
> TIA,
>
> Sheila Crowe
>
> Montana State University ResNet
We have DNS blocks on malware via various DNSRBLs. Any web traffic is redir=
ected to a box that via the resources at:
https://zeustracker.abuse.ch/
determines if the particular 'hit' is zeus.
Clients with more than 5 HTTP GETs, or any HTTP POSTs, that match Zeus are =
contacted (wired) or contacted+access revoked (wireless or VPN).
-James
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html
___________________________________________________
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
___________________________________________________ You are subscribed to t=
he ResNet-L mailing list.
To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html ________________________________________________=
___
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
--_000_2F56B11089DC8D49AC1DC326C351C163061E2C3988EXCMSmsumonta_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40"><head><meta http-equiv=3DContent-Type content=
=3D"text/html; charset=3Diso-8859-1"><meta name=3DGenerator content=3D"Micr=
osoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
{mso-style-priority:99;
mso-style-link:"Balloon Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:8.0pt;
font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
{mso-style-name:"Balloon Text Char";
mso-style-priority:99;
mso-style-link:"Balloon Text";
font-family:"Tahoma","sans-serif";}
span.EmailStyle20
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue vli=
nk=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span style=3D'f=
ont-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>I agree w=
ith this whole heartedly.=A0 I’m not a forensics expert because I wen=
t to a conference in SC once years ago, and the seriousness of a Bot of thi=
s kind needs specialized law enforcement.=A0 I plan on proving the inside L=
AN/outside WAN Command & Control server today with some blacklisting of=
known domains and IP’s used and tracked.=A0 If the Botmaster install=
ed another C&C server on the LAN segment, I’ll be able to identif=
y the traffic from our packet captures or from the configuration files that=
can be read from an infected machine.=A0 If the source address spoofing is=
decoded and shows internal, we already have a plan to involve the authorit=
ies.=A0 I also have been keeping the captures and infection lists as data.=
=A0 I’m lucky to have support from others working the same angle tryi=
ng to decipher if it’s block and mitigate an external attack, or iden=
tify and contact for an internal investigation.=A0 <o:p></o:p></span></p><p=
class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","s=
ans-serif";color:#1F497D'><o:p> </o:p></span></p><p class=3DMsoNormal>=
<span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1=
F497D'>The rest, you’ll not get an argument from me, considering I us=
e a Mac as a personal preference for many reasons.=A0 The trend is that a f=
alse sense of security is felt by some because of Apple’s track recor=
d in the past.=A0 With the new Intel chips, virtualization, and even softwa=
re compatibility of processor architecture have opened the doors to some vu=
lnerabilities.=A0 When the machine came into the center after identificatio=
n, the talk was that it was clean because it was a Mac, and a brand new one=
.=A0 JSON and java vulnerabilities aside, there are other avenues for the i=
ntelligent person to hack just about anything with a network connection. <o=
:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;fo=
nt-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p=
><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri"=
,"sans-serif";color:#1F497D'> Your math, being sound, shows known conclusio=
ns in today’s environment.=A0 I agree tomorrow might be totally diffe=
rent.=A0 Yesterday my flip phone was amazing, today my smartphone is a busi=
ness wonder that is more than I need.=A0 Tablet technology, concepts like M=
icrosoft’s tables for restaurants, TV’s that integrate multiple=
network devices, are taxing support personnel harder than ever as the whir=
lwind speeds up.=A0 I never worried when I was on my Commodore Vic 20, or t=
he Kaypro10 for “mobility”.=A0 When viruses that played yankee =
doodle dandy on a certain day, it was funny.=A0 I don’t think anyone =
in IT back in those days thought that was going to be the scale, and knew i=
t was going to get worse.=A0 As Mac sales increase, and compatibility with =
windows services are more integrated, we’ll start seeing even more fr=
om that platform. =A0Soon enough, attacks will be as platform specific and =
abundant as Android vs. Blackberry infections.=A0 PC vs. Mac is always goin=
g to be disputed, no matter the level of tech.<o:p></o:p></span></p><p clas=
s=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-s=
erif";color:#1F497D'><o:p> </o:p></span></p><p class=3DMsoNormal><span=
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D=
'>Now they have a bios virus variant that re-infects machines on rebooting.=
=A0 Spyeye/Zeus bots have joined into a hybrid, adding encryption to some c=
onfiguration files to make tracking harder.=A0 Even if you can track everyt=
hing down, there are backdoors installed that aren’t taken care of in=
standard cleaning practices.=A0 My antivirus suite doesn’t have a &#=
8220;nuke from orbit” button I’d love as a feature.=A0 We all d=
o everything we can to protect our users, even from themselves, spending bu=
dget money we need for other projects on higher security and a better postu=
re of logging access to identify issues as quickly as possible and removing=
them.=A0 <o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-si=
ze:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:=
p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-fami=
ly:"Calibri","sans-serif";color:#1F497D'>The statement of this group being =
more enlightened was left from the quoted text.=A0 It’s the general M=
ac community that has been lulled into a false sense of security.=A0 An inf=
ected Mac, once on the network, gives access to malicious people looking to=
grow their zombies.=A0 Cost of cleaning in that case? 1 Mac allows access =
for the Botmaster to infect 40 vulnerable machines.=A0 1 Mac just cost a lo=
t of support and trouble because the user believed they are safe and don=
217;t need to be scanning for compromises as Windows users have been taught=
over the years.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'f=
ont-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbs=
p;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;fon=
t-family:"Calibri","sans-serif";color:#1F497D'>An ounce of education saves =
a lot of trouble.=A0 I learn every day to stay educated with the trends, wh=
ich are changing faster than my hair color.=A0 WEP 40bit is fine encryption=
for any wireless right??? Hasn’t been long since that statement was =
believed truth.=A0 <o:p></o:p></span></p><p class=3DMsoNormal><span style=
=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p=
> </o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0p=
t;font-family:"Calibri","sans-serif";color:#1F497D'> =A0=A0<a href=3D"https=
://blog.trendmicro.com/full-analysis-of-the-zeus-licat-trojan/">https://blo=
g.trendmicro.com/full-analysis-of-the-zeus-licat-trojan/</a>=A0 </span><spa=
n style=3D'font-size:11.0pt;font-family:Wingdings;color:#1F497D'>=DF</span>=
<span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1=
F497D'> good information from trend micro for those interested in what thin=
gs are getting like in the Bot world, and the column on the right has infor=
mation on the new hybrid Bots.=A0 <o:p></o:p></span></p><p class=3DMsoNorma=
l><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:=
#1F497D'><o:p> </o:p></span></p><p class=3DMsoNormal><span style=3D'fo=
nt-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> =
;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font=
-family:"Calibri","sans-serif";color:#1F497D'>Jeremy Hendricks<o:p></o:p></=
span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"=
Calibri","sans-serif";color:#1F497D'>Montana State University<o:p></o:p></s=
pan></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"C=
alibri","sans-serif";color:#1F497D'>AUXSVS/ResNet<o:p></o:p></span></p><p c=
lass=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","san=
s-serif";color:#1F497D'>406-994-1929<o:p></o:p></span></p><p class=3DMsoNor=
mal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";colo=
r:#1F497D'><o:p> </o:p></span></p><p class=3DMsoNormal><span style=3D'=
font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>“P=
roactive or reactive, the issue will have to be addressed.=A0 The differenc=
e is the Pucker Factor” - anon<o:p></o:p></span></p><p class=3DMsoNor=
mal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";colo=
r:#1F497D'><o:p> </o:p></span></p><p class=3DMsoNormal><span style=3D'=
font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nb=
sp;</o:p></span></p><p class=3DMsoNormal><b><span style=3D'font-size:10.0pt=
;font-family:"Tahoma","sans-serif"'>From:</span></b><span style=3D'font-siz=
e:10.0pt;font-family:"Tahoma","sans-serif"'> Resnet Forum [mailto:RESNET-L@=
LISTSERV.ND.EDU] <b>On Behalf Of </b>Doughty, Marc<br><b>Sent:</b> Monday, =
September 19, 2011 10:37 AM<br><b>To:</b> RESNET-L@LISTSERV.ND.EDU<br><b>Su=
bject:</b> Re: Zeus botnet anyone?<o:p></o:p></span></p><p class=3DMsoNorma=
l><o:p> </o:p></p><p class=3DMsoNormal style=3D'margin-bottom:12.0pt'>=
If the 'master' is on campus, would it be wise to engage your local FBI off=
ice and offer them a chance to glean some data from it before you pull the =
plug? They might want to grab the machine and set it up behind a honeypot o=
r something so they can track the source of the infection on a larger scale=
.<br><br>Also: "at least the ones in denial that Mac's can get nasty v=
irus/Trojan/bot infections?"<br><br>I'm a big proponent of the 'Mac's =
are pretty safe' theory. The difference between the two being that on these=
Macs I'll bet you can run ClamAV once and they'll be clean, while on Windo=
ws they would each need many hours of 'cleanup' to get de-loused. Basically=
:<br><br><b>Percent of Windows machines that get infected * Number of Windo=
ws machines * time needed to clean each =3D bigger than cost of antivirus c=
ontract</b><br><br>while<br><br><b>Percent of Macs that get infected * Numb=
er of Macs * time needed to clean each =3D smaller than cost of AV contract=
</b><br clear=3Dall><br>I think the math/economics of this work out to show=
that if you've been paying for Mac antivirus for the last decade, you've b=
een getting very little return on investment compared to not paying and dea=
ling with the occasional cleanup. That math could change any day, but until=
it does, I'm comfy recommending users to take it easy.<br><br>- Marc Dough=
ty<br>"If you aren't sure who is the give-way vessel, you are the give=
-way vessel."<br><br><o:p></o:p></p><div><p class=3DMsoNormal>On Fri, =
Sep 16, 2011 at 4:38 PM, Hendricks, Jeremy <<a href=3D"mailto:jeremy@mon=
tana.edu">jeremy@montana.edu</a>> wrote:<o:p></o:p></p><p class=3DMsoNor=
mal>We just identified the Botnet as Zeus. The infection started slow=
and acted like a misconfiguration or equipment failure. Then it took=
off and the DDoS started. We've been lucky that it's only in one bro=
adcast domain. We're brute forcing the issue for now by removing infe=
cted machines.<br><br>Identification was done through a trend of applicatio=
n/JSON traffic. 2 of the 20+ machines that came in for inspection wer=
e MacBook's. (Did I just hear the Mac community draw a breath, =
at least the ones in denial that Mac's can get nasty virus/Trojan/bot infec=
tions? Yes, I know this list is more enlightened) With the JSON=
itch, our desktop support specialist found an IP and separate URL that mat=
ches Zeus in the Java config files.<br><br>Myself and counterparts in centr=
al IT believe the botmaster is on campus in housing. That's the golde=
n egg I'm really searching for.<br><br>For those that have dealt with Zeus,=
and knowing it's nature, do you even feel safe cleaning the OS with all th=
e backdoor options of re-infection? Our volume and staff levels will =
make it difficult to force a reload of every machine that we've identified =
and removed from the network.<br><br>Zeustracker doesn't have our domain or=
IP addresses listed. The Botmaster even noticed the management serve=
r we use for port shutdowns, and spoofed the IP of that server to cause an =
IP conflict and try to stop us.<br><br>Charles ---> no, it doesn't act a=
s a DHCP server. All traffic is IP spoofed with the MAC addresses the=
only identifier of the infected hosts. Only 5 addresses have been th=
e destination of the DDoS. Each run uses a different protocol as well=
.<br><span style=3D'color:#888888'><br><br>Jeremy Hendricks<br>Montana Stat=
e University<br>AUXSVS/ResNet<br><a href=3D"tel:406-994-1929">406-994-1929<=
/a></span><o:p></o:p></p><div><p class=3DMsoNormal style=3D'margin-bottom:1=
2.0pt'><br><br><br>-----Original Message-----<br>From: Resnet Forum [mailto=
:<a href=3D"mailto:RESNET-L@LISTSERV.ND.EDU">RESNET-L@LISTSERV.ND.EDU</a>] =
On Behalf Of James J J Hooper<br>Sent: Friday, September 16, 2011 11:09 AM<=
br>To: <a href=3D"mailto:RESNET-L@LISTSERV.ND.EDU">RESNET-L@LISTSERV.ND.EDU=
</a><br>Subject: Re: Zeus botnet anyone?<o:p></o:p></p></div><div><div><p c=
lass=3DMsoNormal>On 16/09/2011 17:56, Crowe, Sheila wrote:<br>> Hey Ever=
yone,<br>><br>> Does anyone have any experience with ridding your net=
work of this scourge?<br>> We believe that one of our VLANs may include =
a “bot master” and he’s<br>> killing us over there. It=
has taken us this long to just find out what<br>> the problem is. Any t=
ips, hints, references for Voodoo docs,<br>> questions…all are wel=
come.<br>><br>> TIA,<br>><br>> Sheila Crowe<br>><br>> Mon=
tana State University ResNet<br><br>We have DNS blocks on malware via vario=
us DNSRBLs. Any web traffic is redirected to a box that via the resources a=
t:<br><a href=3D"https://zeustracker.abuse.ch/" target=3D"_blank">https://z=
eustracker.abuse.ch/</a><br>determines if the particular 'hit' is zeus.<br>=
<br>Clients with more than 5 HTTP GETs, or any HTTP POSTs, that match Zeus =
are contacted (wired) or contacted+access revoked (wireless or VPN).<br><br=
>-James<br><br>___________________________________________________<br>You a=
re subscribed to the ResNet-L mailing list.<br><br>To subscribe, unsubscrib=
e or search the archives, go to <a href=3D"http://LISTSERV.ND.EDU/archives/=
resnet-l.html" target=3D"_blank">http://LISTSERV.ND.EDU/archives/resnet-l.h=
tml</a><br>___________________________________________________<br><br>_____=
______________________________________________<br>You are subscribed to the=
ResNet-L mailing list.<br><br>To subscribe, unsubscribe or search the arch=
ives,<br>go to <a href=3D"http://LISTSERV.ND.EDU/archives/resnet-l.html" ta=
rget=3D"_blank">http://LISTSERV.ND.EDU/archives/resnet-l.html</a><br>______=
_____________________________________________<o:p></o:p></p></div></div></d=
iv><p class=3DMsoNormal><br>_______________________________________________=
____ You are subscribed to the ResNet-L mailing list. <o:p></o:p></p><p>To =
subscribe, unsubscribe or search the archives, go to <a href=3D"http://LIST=
SERV.ND.EDU/archives/resnet-l.html">http://LISTSERV.ND.EDU/archives/resnet-=
l.html</a> ___________________________________________________ <o:p></o:p><=
/p></div></body></html>=
___________________________________________________
You are subscribed to the ResNet-L mailing list.
<p>
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
--_000_2F56B11089DC8D49AC1DC326C351C163061E2C3988EXCMSmsumonta_--