Written by v2r on June 27, 2011 – 7:05 pm -
The TDSS botnet, now in its 4th generation, is seriously sophisticated malware, which is why we've spent so much time writing about it: the revision of the paper The Evolution of TDL: Conquering x64 that will be up on the white papers page shortly runs to 54 pages and includes some highly technical analysis, including the detail on the recent plugin described in a blog earlier today. So how does this new component actually work?
When a PC is infected by a bot, it becomes part of a network of other compromised machines which we call a botnet. So now the criminal who is managing the botnet needs to be able to issue instructions to the malware on each infected machine (zombie). And, of course, communication often needs to go the other way: depending on what the botnet is being used for, it may well have to return data to the "botmaster". A very common way of implementing two-way communication is by setting up some machines as "Command & Control" (C&C) server: this is a malicious version of the client/server model, where a single server may provide services to many client PCs. And it still works very well, but there is a drawback to this approach, as far as the criminals are concerned.
If we're able to trace and close down some or all of the C&C servers which are supplying information to the infected "zombie" PCs and telling them what to do, then we cut the head off the dragon: the zombies that rely on a server for their instructions are no longer able to carry out the wishes of the botmaster. (Or dragonmaster, if you prefer…)
Using the Kademilia protocol described in our previous blog, the botmaster is able to get round the weakness of the C&C approach, using a sort of collective consciousness approach where infected machines are both zombie and C&C server, or you might say both client and server. All botnets use a perverted form of distributed processing, but this approach makes good use of distributed data, too.
Rather than having a few machines with all the information and running the show, the information is shared between all the machines in the network. Even though individual machines are joining the botnet and others are dropping out, it doesn't particularly matter: a zombie can get the information it needs from its neighbours, and it knows where they are because it keeps a sort of virtual phonebook hidden on the hard disk.The only time it needs to contact the C&C server is when the number of neighbouring nodes drops below ten: a bit like a householder who realizes that his neighbours are all moving away and he needs to order a new telephone directory.
This doesn't make TDL4 invulnerable, by any means, but it does mean that it's harder to disable large swatches of the botnet at a stroke. But no-one ever said that TDSS, with its tricks for infecting 64bit systems and knocking out the competition, was easy to deal with.
David Harley CITP FBCS CISSP
ESET Senior Research Fellow
read source...
Tags:
Aleksandr Matrosov,
Botnet,
C&C,
client-server,
Command and Control,
computer security,
David Harley,
ESET Russia,
Eugene Rodionov,
Kademilia,
malware remove,
TDL4,
TDSS,
virus remove,
zombiePosted in
Virus removal tools |
Remove Virus, Malware, Trojans - Computer virus Removal tools
Nothing can be worse than a malware infected PC. With its domination on how you browse and an irritating spray of websites that you never opened, malware can make regular browsing experience a nightmare. Not just that, spuriously it might pass on critical information as well.
Thank God for antimalware programmers, browsing gets a little sane with anti malware. It catches such malicious programs, takes them off and revive the same browsing experience.
Computer Malware is a Real Problem
You never know what purpose a malware has been designed with until you catch it. Is it to track your usernames and passwords, to catch your browsing history, or your shopping habits?
Depending on who makes them, the purpose of malware differs; yet collectively they remain a big threat. They operate in disguise and not only risk your personal information but consume processing power and bandwidth as well.
Common Sources of Catching a Malware
If you have been wondering how your PC got infected and why antimalware program become crucial for you, here are some pointers for you:
Malicious sites: If you by mistake landed on sites that looked suspicious, there is a high possibility that you got a malware from there.
Third party packages: If you keep trying unreliable third party software as a habit, chances are you have many malware running on your PC. Most of the malicious marketers club their malware with popular applications. Next time, you install an application, keep the anti-virus program active.
Torrent downloads: While people may not accept, piracy is a common practice and thanks to torrents, malware programmers find a new outlet for spreading their programs. If you have downloaded files through torrents, especially through seeders not known for reliable downloads, you might have downloaded malware without even knowing about it.
If your PC shows sign of being infected by malware, your best bet is to download a reliable anti malware program now and run it to catch the bad boys!
Trust us, further you delay running anti malware programs, worse the situation gets.
Computer Viruses, Malwares, Trojans - Remove
Each year the particular problems via personal computer malware cost US corporations immeasureable dollars. These pricing is with missing efficiency, however everlasting loss in essential organization info. Perhaps, nearly all if not all attacks are avoidable with the appropriate comprehension, education and defense. Do not be another sufferer, take the actions today to make certain safety and recovery in the event the most detrimental need to take place.Initial, let’s realize personal computer malware. Usually the phrase malware is employed to explain all adware and spyware. Technically speaking, there are malware, rootkits, Trojan horses, viruses as well as spy ware. The actual strike approach may differ however they are almost all harmful.A virus is a plan that goes by itself and also illegal copies themselves. It could influence documents or perhaps the trunk field and will delete all your files. The particular “Melissa” and “I Really like You” viruses gained worldwide interest. Any rootkit or even Trojan viruses horse allows use of one’s body without you knowing. Usually they look just like a beneficial software application but in fact they may be again or snare doorways.A pc earthworm is a self-replicating computer program. That utilizes a network to deliver duplicates involving by itself with nodes. After on the method, viruses don’t need to put on an additional software and can run by themselves. Viruses create a rejection of service assault generating the system not used. In general, earthworms focus on the network and infections attack files.