词条 | Grum botnet |
释义 |
The Grum botnet, also known by its alias Tedroo and Reddyb, was a botnet mostly involved in sending pharmaceutical spam e-mails.[1] Once the world's largest botnet, Grum can be traced back to as early as 2008.[2] At the time of its shutdown in July 2012, Grum was reportedly the world's 3rd largest botnet,[3] responsible for 18% of worldwide spam traffic.[4][5] Grum relies on two types of control servers for its operation. One type is used to push configuration updates to the infected computers, and the other is used to tell the botnet what spam emails to send.[6] In July 2010, the Grum botnet consisted of an estimated 560,000–840,000 computers infected with the Grum rootkit.[7][8] The botnet alone delivered about 39.9 billion[9] spam messages in March 2010, equating to approximately 26% of the total global spam volume, temporarily making it the world's then-largest botnet.[10][11] Late in 2010, the botnet seemed to be growing, as its output increased roughly by 51% in comparison to its output in 2009 and early 2010.[12][13] It used a panel written in PHP to control the botnet.[14] Botnet takedownIn July 2012, a malware intelligence company published an analysis of the botnet's command and control servers located in the Netherlands, Panama, and Russia. It was later reported that the Dutch Colo/ISP soon after seized two secondary servers responsible for sending spam instructions after their existence was made public.[15] Within one day, the Panamanian ISP hosting one of Grum's primary servers followed suit and shut down their server.[16] The cybercriminals behind Grum quickly responded by sending instructions through six newly established servers in Ukraine.[17] FireEye connected with Spamhaus, CERT-GIB, and an anonymous researcher to shut down the remaining six C&C servers, officially knocking down the botnet.[17] Grum botnet zombie clean-upThere was a sinkhole running on some of the former IP addresses of the Grumbot C&C servers. A feed from the sinkhole was processed via both Shadowserver and abusix to inform the Point of Contact at an ISP that has an infected IP addresses. ISP's are asked to contact their customers about the infections to have the malware cleaned up. Shadowserver.org will inform the users of their service once per day and Abusix sends out a X-ARF (extended version Abuse Reporting Format) report every hour. See also
References1. ^{{cite web|url=http://www.m86security.com/labs/spambotitem.asp?article=898 |title=Grum |publisher=M86 Security |date=2009-04-20 |accessdate=2010-07-30}} {{Botnets}}2. ^{{cite web |author=Atif Mushtaq |url=http://blog.fireeye.com/research/2012/07/killing-the-beast-part-5.html |title=Killing the Beast - Part 5 |publisher=FireEye |date=2012-07-09 |accessdate=2012-07-11}} 3. ^{{cite web |url=http://www.fireeye.com/blog/technical/botnet-activities-research/2012/07/grum-botnet-no-longer-safe-havens.html |title=Grum, World’s Third-Largest Botnet, Knocked Down | FireEye Blog |first=Atif |last=Mushtaq |publisher=Fireeye.com |date=2012-07-18 |accessdate=2014-01-09}} 4. ^{{Cite news |url=https://www.bbc.com/news/technology-18898971 |title=Huge spam botnet Grum is taken out by security researchers |date=19 July 2012 |work=BBC News}} 5. ^{{cite news|url=http://bits.blogs.nytimes.com/2012/07/18/cybersecurity-researchers-say-they-took-down-worlds-third-largest-botnet/?src=twr |title=Researchers Say They Took Down World’s Third-Largest Botnet |publisher=New York Times |date=2012-07-18 |accessdate=2012-07-18}} 6. ^{{cite web|url=http://news.idg.no/cw/art.cfm?id=DA2D14C0-0D73-1D2B-F5A08C7983839E37 |title=One of the world's largest spam botnets still alive after suffering significant blow |publisher=IDG |date=2012-07-17 |accessdate=2012-07-17}} 7. ^{{cite web|url=http://www.zdnet.com/blog/security/research-small-diy-botnets-prevalent-in-enterprise-networks/4485 |title=Research: Small DIY botnets prevalent in enterprise networks |publisher=ZDNet |date= |accessdate=2010-07-30}} 8. ^{{cite web|url=http://www.messagelabs.com.sg/resources/blog.aspx?link=http://www.symantec.com/connect/node/1029851 |title=MessageLabs Blog - Evaluating Botnet Capacity |publisher=Messagelabs.com.sg |date= |accessdate=2010-07-30}} 9. ^{{cite web|url=http://www.darkreading.com/securityservices/security/perimeter/showArticle.jhtml?articleID=220300610 |title=Which Botnet Is Worst? Report Offers New Perspective On Spam Growth - botnets/Security |publisher=DarkReading |date= |accessdate=2010-07-30}} 10. ^{{cite web|url=http://www.securecomputing.net.au/News/168557,grum-and-rustock-botnets-drive-spam-to-new-levels.aspx |title=Grum and Rustock botnets drive spam to new levels|publisher=Securecomputing.net.au |date=2010-03-02 |accessdate=2010-07-30}} 11. ^{{cite web|last=Whitney |first=Lance |url=http://news.cnet.com/8301-1009_3-10462103-83.html |title=Botnets cause surge in February spam | Security - CNET News |publisher=News.cnet.com |date=2010-03-02 |accessdate=2010-07-30}} 12. ^{{cite web|author=James Wray and Ulf Stabe |url=http://www.thetechherald.com/article.php/201009/5308/Spam-volumes-surge-thanks-Grum-and-Rustock-botnets |title=Spam volumes surge thanks Grum and Rustock botnets - Security |publisher=Thetechherald.com |date=2010-03-01 |accessdate=2010-07-30}} 13. ^{{cite web|url=http://www.bizreport.com/2009/09/messagelabs_botnets_a_threat_to_email_marketing.html |title=MessageLabs: Botnets a threat to email marketing - Email Marketing |publisher=BizReport |date=2009-09-30 |accessdate=2010-07-30}} 14. ^{{cite web|author=Brian Krebs |url=http://krebsonsecurity.com/2012/08/inside-the-grum-botnet/|title=Inside the Grum botnet|date=2012-08-20}} 15. ^{{cite web|author=Steve Ragan |url=http://www.securityweek.com/dutch-police-takedown-ccs-used-grum-botnet |title=Dutch Police Takedown C&Cs Used by Grum Botnet |publisher=Security Week |date=2012-07-17 |accessdate=2012-07-17}} 16. ^{{cite web|author=Alex Fitzgerald |url=http://mashable.com/2012/07/19/spam-botnet-taken-down/ |title=Botnet Responsible for 18% of World’s Spam Knocked Offline |publisher=Mashable |date=2012-07-19 |accessdate=2012-07-19}} 17. ^1 {{cite web|author=Atif Mushtaq |url=https://www.fireeye.com/blog/threat-research/2012/07/grum-botnet-no-longer-safe-havens.html |title=Grum, World's Third-Largest Botnet, Knocked Down |publisher=FireEye |date=2012-07-19 |accessdate=2012-07-19}} 5 : Computer network security|Multi-agent systems|Distributed computing projects|Spamming|Botnets |
随便看 |
|
开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。