Microsoft knocks massive spambot offline
By Nicole Kobie
Posted on 18 Mar 2011 at 07:59
Microsoft has helped knock offline a massive spam botnet, known as Rustock.
Working alongside network security firm FireEye, the University of Washington, the Dutch High Tech Crime Unit and Chinese authorities, Microsoft used “knowledge gained” in last year’s takedown of Waledac to target “a larger, more notorious and complex botnet known as Rustock,” said Richard Boscovich, senior attorney for Microsoft’s digital crimes unit (DCU), in a blog post.
A large botnet can be used for almost any cybercrime a bot-herder can dream up
Rustock has infected a million computers worldwide, and sends as many as a billion spam emails a day, Microsoft claimed.
“Although its behaviour has fluctuated over time, Rustock has been reported to be among the world’s largest spambots, at times capable of sending 30 billion spam emails per day," said Boscovich.
"DCU researchers watched a single Rustock-infected computer send 7,500 spam emails in just 45 minutes – a rate of 240,000 spam mails per day. Moreover, much of the spam observed coming from Rustock posed a danger to public health, advertising counterfeit or unapproved knock-off versions of pharmaceuticals.”
While Rustock didn’t send malware, spam is a “symptom of greater threats to internet health,” said Boscovich.
“Although Rustock’s primary use appears to have been to send spam, it’s important to note that a large botnet can be used for almost any cybercrime a bot-herder can dream up," he said. "Botnets are powerful and, with a simple command, can be switched from a spambot to a password thief or DDOS attacker.”
Legal and technical measures
Microsoft used legal and technical measures to cut Rustock off, shutting down the communication between the botnet’s command and control centre and the computers infected by it.
In order to claim control of Rustock’s servers, Microsoft argued to US courts that the as-yet-unknown operators of the botnet were infringing the software company’s trademark by using the Microsoft logo in spam it sent out.
“However, Rustock’s infrastructure was much more complicated than Waledac’s, relying on hard-coded Internet Protocol addresses rather than domain names and peer-to-peer command and control servers to control the botnet,” said Boscovich.
“To be confident that the bot could not be quickly shifted to new infrastructure, we sought and obtained a court order allowing us to work with the US Marshals Service to physically capture evidence onsite and, in some cases, take the affected servers from hosting providers for analysis,” he said, saying servers were seized from five hosting providers in seven cities.
Microsoft warned malware criminals that it wasn’t finished with botnets: “We will continue to invest similar operations in the future as well in our mission to annihilate botnets and make the internet a safer place for everyone,” said Boscovich.
From around the web
Good news - but there is more to do!
This is like intercepting tonnes of cocaine - it gets the symptom, not the cause. Next: go for those who profit from this spam.
By Dave2207 on 18 Mar 2011 ![]()
@Dave2207
Sadly going for those who profit from the spam or drugs has been totally ineffective so far.
By tirons1 on 18 Mar 2011 ![]()
http://www.ppshopping.us
good
By lili84 on 18 Mar 2011 ![]()
I wish MS would go for the cause...
...the vulnerabilities and ease of use so loved by spambots on Windows PCs.
By SwissMac on 18 Mar 2011 ![]()
And in first place after 5 seconds, Apple.
By chapelgarth on 18 Mar 2011 ![]()
advertisement
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Why you have to be left in the dark on OS patches
- Publishing your email address isn't a security disaster
- Why antivirus is fighting a losing battle in your office
- Four year olds used to steal their parents' data
- An acceptable use policy for your kids
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
advertisement
