Tuesday, 02 December 2008 07:45

Srizbi down but not quite out

By
The Srizbi botnet has proved sufficiently robust to partially recover from the isolation of its command and control servers. So much for claims that it was 'completely defunct'.

When hosting provider McColo was taken down on November 11, email filtering  operators noted a drop in spam volumes of between two-thirds and three-quarters.

Later that month, a statement from MessageLabs attributed to senior anti-spam technologist at Matt Sergeant said "Srizbi, having once been responsible for 50 per cent of all spam, is now completely defunct. Without this botnet, spam levels won't return to what they had been."

That statement appears to have been premature.

It seems that the Srizbi code had been developed with an eye to recovering from such a situation.

If a Srizbi bot loses contact with the server, it uses an algorithm to generate a seemingly random (but time-dependent) domain name, at which it attempts to contact a server.

So all that was necessary was to register one of those names in time for the bots to attempt to contact it.

While security firm FireEye spent at least $1500 registering names that the botnet would attempt to use, "as money is not infinite, soon the new domains will be available for registration by anyone, including the Botnet owner, or someone who wishes to be a Botnet owner."

And that, it appears, is what happened. Someone registered a set of domain names and used them to regain control over the Srizbi botnet.

According to the Washington Post, VeriSign, Microsoft and the US Computer Emergency Readiness Team (US-CERT) had been asked to assist in either buying up (or tying up) the domains ahead of time, with no apparent response.

The new Srizbi servers located in Estonia were subsequently shut down before much spam could be pumped out, according to The Register, although one  server located in Germany was still active at the time of the report.

According to FireEye, the most active botnets are currently Pushdo/Cutwail and Bobax/Kraken.

Read 4204 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here




EXL AI IN ACTION VIRTUAL EVENT 20 MARCH 2025

Industry leaders are looking to transform their businesses and achieve measurable outcomes with AI.

As organisations across APAC navigate the complexities of AI adoption, this must-attend event brings together industry leaders, real-world demonstrations, and visionary panel discussions to bridge the gap between proof-of-concepts and enterprise-wide AI implementation.

Learn how to overcome common challenges in deploying AI at scale.​

Unlock cost savings, efficiency, and better customer experiences with AI.

Discover how industry expertise and data intelligence enable practical AI deployment.

Register for the event now!

REGISTER!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

BACK TO HOME PAGE
Stephen Withers

Stephen Withers is one of Australia¹s most experienced IT journalists, having begun his career in the days of 8-bit 'microcomputers'. He covers the gamut from gadgets to enterprise systems. In previous lives he has been an academic, a systems programmer, an IT support manager, and an online services manager. Stephen holds an honours degree in Management Sciences and a PhD in Industrial and Business Studies.

Share News tips for the iTWire Journalists? Your tip will be anonymous

Subscribe to Newsletter

*  Enter the security code shown: img0

WEBINARS & EVENTS

CYBERSECURITY

PEOPLE MOVES

GUEST ARTICLES

Guest Opinion

ITWIRETV & INTERVIEWS

RESEARCH & CASE STUDIES

Channel News

Comments