Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 18th, 2012, 09:12 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,190
Default Researchers Say They Took Down World’s Third-Largest Botnet

Quote:
By NICOLE PERLROTH

On Wednesday, computer security experts took down Grum, the world’s third-largest botnet, a cluster of infected computers used by cybercriminals to send spam to millions of people. Grum, computer security experts say, was responsible for roughly 18 percent of global spam, or 18 billion spam messages a day.
http://bits.blogs.nytimes.com/2012/0...argest-botnet/
  #2  
Old July 19th, 2012, 12:31 AM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,126
Post Re: Researchers Say They Took Down World’s Third-Largest Botnet

Also from: SecurityWeek
Quote:
Researchers at malware intelligence firm FireEye are reporting that Dutch authorities have pulled the plug on two secondary servers used by the Grum botnet. The removal of the servers shines light on how quickly some law enforcement agencies work, given that proof of their existence is just over a week old.

Last week, FireEye published the details on four servers, actively controlling the Grum botnet. These servers, two in the Netherlands, one in Panama, and one in Russia, were split into primary and secondary roles. The backup C&Cs were located in the Netherlands, and once word of their existence was released, Dutch authorities quickly seized them.
  #3  
Old July 19th, 2012, 01:21 PM
Baserk's Avatar
Baserk Baserk is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Amstelodamum
Posts: 969
Default Re: Researchers Say They Took Down World’s Third-Largest Botnet

The Grum botnet seems completely kaput by now. On the FireEye blog, Atif Mushtaq wrote;

'I am glad to announce that, after three days of effort, the Grum botnet has finally been knocked down. All the known command and control (CnC) servers are dead, leaving their zombies orphaned.
How it all happened is a long story, but I would like to summarize it for you.
The state of the Grum botnet has changed since we last talked (see previous posts here and here for a look back). On July 16, I reported that while CnC servers in Panama and Russia were alive, shutting down the Dutch server had at least made a dent in this botnet. On the morning of July 17, I got the news that the server in Panama was no longer active. The ISP owning this server at last buckled under the pressure applied by the community. It was great news. The shutdown of the Panamanian server meant a lot. I explained in my earlier post that Grum was comprised of two different segments. One was being controlled from Panama and one from Russia. ...
' link
__________________
ROMANES EUNT DOMUS
  #4  
Old July 19th, 2012, 02:21 PM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Researchers Say They Took Down World’s Third-Largest Botnet

Always good to hear this kind of news.
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #5  
Old July 19th, 2012, 02:23 PM
sukarof's Avatar
sukarof sukarof is offline
Very Frequent Poster
 
Join Date: Jun 2004
Location: Stockholm Sweden
Posts: 1,605
Default Re: Researchers Say They Took Down World’s Third-Largest Botnet

If this is true: Kudos to them! Way more cool than make one
__________________
OS: Windows 8 PRO 64bit
Imaging: Macrium Reflect Pro ver. 5. Image fo Windows. Virtualization: VMware Workstation .Passwordmanager: Lastpass Premium
AV/FW: Kaspersky Internet Security 2013 Currently testing: AX64 Time Machine.
  #6  
Old July 23rd, 2012, 09:07 PM
Dermot7's Avatar
Dermot7 Dermot7 is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Surrey, England.
Posts: 1,842
Default Re: Researchers Say They Took Down World’s Third-Largest Botnet

Quote:
As expected, the operators behind Grum are trying their best to reclaim their botnet. In the absence of any built-in fallback mechanisms, the bot herders used another fallback mechanism that is called money. Over the weekend we found that the Ukrainian ISP SteepHost removed the null route on three CnCs that were taken down last week. We suspect the bot herders must have paid a large amount of money in order to get access to these servers.
http://blog.fireeye.com/research/201...ey-factor.html
__________________
A man's pride shall bring him low: but honour shall uphold the humble in spirit: Proverbs 29,23.
"Only the wasteful virtues earn the sun": William Butler Yeats, April 27, 1916.
  #7  
Old July 24th, 2012, 04:08 AM
rollers rollers is offline
Frequent Poster
 
Join Date: Sep 2004
Posts: 389
Default Re: Researchers Say They Took Down World’s Third-Largest Botnet

I do hope it stays like that. The amount of spam in my gmail spam folder has dropped off to almost zero, only had one yesterday instead of the usual 15 to 20 a day.
  #8  
Old July 28th, 2012, 04:00 AM
rollers rollers is offline
Frequent Poster
 
Join Date: Sep 2004
Posts: 389
Default Re: Researchers Say They Took Down World’s Third-Largest Botnet

Quote:
Originally Posted by rollers
I do hope it stays like that. The amount of spam in my gmail spam folder has dropped off to almost zero, only had one yesterday instead of the usual 15 to 20 a day.
Ok..................I take that back now, seems it was a temporary blip..........now back up to normal levels of junk again
  #9  
Old July 28th, 2012, 09:36 PM
Chiron Chiron is offline
Regular Poster
 
Join Date: Jun 2010
Posts: 173
Default Re: Researchers Say They Took Down World’s Third-Largest Botnet

Quote:
Originally Posted by rollers
Ok..................I take that back now, seems it was a temporary blip..........now back up to normal levels of junk again
You may want to see my article about How to Report Spam. You may find it of some assistance.
__________________
How to Stay Safe While Online
  #10  
Old August 6th, 2012, 01:42 AM
tomazyk's Avatar
tomazyk tomazyk is offline
Frequent Poster
 
Join Date: Dec 2006
Location: Slovenia
Posts: 601
Default Re: Researchers Say They Took Down World’s Third-Largest Botnet

Here is some interesting inside information regarding Grum takedown: http://techcrunch.com/2012/08/04/gru...spam-networks/
__________________
ESET Nod32 AV • Sandboxie • EMET • OpenDNS
My security setup in detail
• Always remember you're unique, just like everyone else •

  #11  
Old August 20th, 2012, 02:08 PM
Dermot7's Avatar
Dermot7 Dermot7 is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Surrey, England.
Posts: 1,842
Default Re: Researchers Say They Took Down World’s Third-Largest Botnet

Quote:
KrebsOnSecurity has obtained an exclusive look inside the back-end operations of the recently-destroyed Grum spam botnet. It appears that this crime machine was larger and more complex than many experts had imagined. It also looks like my previous research into the identity of the Grum botmaster was right on target.
https://krebsonsecurity.com/2012/08/...e-grum-botnet/
__________________
A man's pride shall bring him low: but honour shall uphold the humble in spirit: Proverbs 29,23.
"Only the wasteful virtues earn the sun": William Butler Yeats, April 27, 1916.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:15 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums