Mega-D Botnet Defeated by FireEye Security Researchers

Sumo3000 By Sumo3000 in Computer Security | 0 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

Thanks to the efforts of Atif Mushtaq, security researcher from FireEye, and two other of his collegues, Mega-D Botnet has been taken down.

Mega-D has been known to be a resilient botnet that took control of 250,000 PCs using command-and-control servers that issue instructions to run spam campaigns on the compromised computers. Also known as Ozdok, Mega-D botnet was picked apart by researchers who discovered just recently how to target the controllers to ultimately take down the botnet.

Botnets such as Mega-D usually receive online commands to carry out various functions such as in the case of Mega-D, initiate spamming campaigns. The task of taking down Mega-D not only involves ceasing the flow of instructions from its command and control servers, but isolates them and points them to servers that FireEye setup to log Mega-D’s check-in actions.

If a botnet is unable to contact its primary controllers, then it usually attempts to contact spare domains which in Mega-D’s case, FireEye setup those as sinkholes to initiate an offensive effort to bring down Mega-D. This effort was orchestrated by FireEye working with the registrars of the spare domain names which Mega-D’s controllers listed in the bot’s programming. The sinkholes setup by security researchers logged about 250,000 Mega-D infected systems.

The whole effort of Atif Mushtaq attempting to take down the Mega-D botnet was successful only by taking an offensive stand. Mega-D accounted for 11.8 percent of spam that security company MessageLabs witnessed in the month of November 2009. Mega-D was first found to be susceptible to defeat in November of 2009 when we wrote about FireEye Striking a blow against the Ozdok/Mega-D Spam Botnet. While some researchers were unclear if Mega-D would get back on its feet, it is now apparent that with unyielding efforts we can beat this notorious botnet.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • StumbleUpon
  • Technorati
  • YahooMyWeb
This entry was posted on 01/5/10 and is filed under Computer Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Poll

How much money have you spent trying to rid your PC of spyware?
View Results
Follow Us on Twitter

Archives

Home Sitemap RSS Feed Privacy Policy End User License Agreement Copyright 2003-2010. Enigma Software Group USA, LLC. All Rights Reserved.