Showing posts with label Malware Traffic. Show all posts
Showing posts with label Malware Traffic. Show all posts

Saturday, 20 June 2015

Research: Botnets Consist Of Average 1700 Computers



In the first quarter of this year were from botnets average 1700 computers, claims ISP Level 3 on the basis of own research ( pdf ). For the study 600 to 1000 Command & Control servers were monitored allow cyber criminals to control infected computers.

The number of computers part of a botnet accounted fluctuated considerably in the first months of this year. So it went in January to an average of 3,763 computers, but this was dropped in March to 338 computers. According to Level 3 is due to the decline in the "vigilance" by the security community. Computers that are part of a botnet are found mainly in China and the United States, each with more than half a million infected machines, followed by Norway with 213,000 "zombies."

Norway was in the first quarter, also the target of the most botnet traffic, followed by the US and Spain. The presence of Norway is explained by a single incident where a botnet server was hosted within a specific hosting environment.

Netherlands

The report also mentioned several times Netherlands. For example, the Netherlands is in fourth place worldwide in countries that generate botnet traffic and in third place in Europe. "From a global perspective, the Netherlands is higher in relation to other European countries. The top 10 listing is primarily due to a large and heavy port scanner which made a number of victims in the Nordic region," says the report. It is further stated that the Netherlands provides a "robust infrastructure," making it "ideal" is to centralize botnets in the region.

Friday, 22 May 2015

Secret Unit Google Fights Against Botnets And Click Fraud


Google has a secret unit of over a hundred people who are working every day with combating botnets click and ad commit fraud. The botnets generate traffic and clicks for ads and would advertisers and advertising platforms billions of euros.

Google is the largest ad provider on the Internet ad fraud and therefore constitutes a serious risk to giant internal. A risk is increasing. "We are at a point which malware is being used mainly for advertising fraud," says Douglas Hunter Google versus Ad Age . The website received a unique insight into the workings of the secret unit, whose existence has not been made ​​public by Google.

Malware

To combat fraud, the ad team analyzes all kinds of malware, which include Google through the online virus scan service VirusTotal receives. By analyzing the malware a click fraud botnet can be mapped. Then look at the traffic that generates the malware. Traffic which malware authors try to make it look as human as possible.

In the Google case "non-human" traffic will encounter the publisher ads showing not paid and the advertiser is no fee will be charged. By now inspire to step outside Google hopes other companies to share their findings and to tackle together ad fraud."Our job is to increase the cost for the fraudsters to a point that advertising fraud no longer interesting for them," concludes De Jager.

Wednesday, 7 January 2015

New Variant of Emotet Malware - "Microsoft Warns of Malware That Steals Passwords"


Microsoft warned their users about malware that steals passwords for various programs and login details for online banking. The Emotet malware is distributed via a spam campaign that is aimed primarily at German Internet users, although 2.3% of the infections was observed in the Netherlands. The email contains a link to a zip file with a known deposit of the bank.



In reality, the zip file contains an .exe file that malware. Once active Emotet tries to steal login details for several German banks. In addition, the passwords for Eudora, Google Desktop, Google Talk, IncrediMail, Mozilla Thunderbird, MSN or Windows Live Messenger, Netscape 6 and Netscape 7, Outlook 2000, Outlook 2002 and Outlook Express, Windows Mail and Windows Live Mail and Yahoo! Messenger sent back to the attackers.

The linked website can download a .zip file that contains an executable file with a long file name to hide its .exe extension such as:

  • de_0000239029_rechnung_scan_hp_28_0000000904_page_2_10_01_05_id_00291002098.exe
  • E-Card_zu_Weichnachten_scan_foto_2834792347_12_2014_21093812_000129_001_004_002910.exe
  • Informationen_Kontobewegung_dezember_2014_de_20_8139_237_90109238_000129_000028_05.exe

According to the software giant let the malware show that it is important to keep security software up-to-date. To share in the event Microsoft's security software is used, users taking the advice to data with the Microsoft Active Protection Service Community (MAPS).