Infesting you with Virus News
 

News

Contributed by: Nono
Date: September 17, 2008
Nono
7
Vote
0

Srizbi and Rustock; Rivals or Siblings?

 

red-spam.jpg

Could it be true? Srizbi and Rustock the two botnets to blame for the increasingly large amount of spam attacks taking place, are not rivals but are in fact are siblings! It was found that the two botnets share the same principle with regards to malware spreading.

Apparently both botnets use a type of malware, Trojan. Exchanger, that comes with illegitimate e-mails. Such e-mails intrigue users with adverts, shocking news headlines etc., seducing users to click on links that once clicked make the users computer apart of a botnet.

According to Fengmin Gong, chief security content officer for anti-botnet software firm FireEye, the first time they noticed this connection between the botnets they were truely surprised. FireEye researchers also speculated that the two botnets are run by one operator, most likely the Russian Business Network, but that theory is not conclusive at this point.

According to the FureEye research team it is pretty clear that Srizbi and Rustock are using same Internet Service Provider. In some cases they also use IPs on alike subnets to host their Command and Control servers - Command and Control servers sharing LANs is very unusual. The research team came to the conclusion that the Botnets are either operated by the same organization or McColo (the datacenter) is a shell corporation in the business of leasing out bandwidth and IP space for malevolent deeds.

9hackers.jpgThe director of security research for SecureWorks, Joe Stewart stated that the Srizbi-Rustock connection is probably just a case of spammers using both zombie networks and not that the controllers of the different botnets are actually in cahoots with each other.

With Rustock bots sending out mail that basically infect PC's with Srizbi, people tend to believe that Srizbi is the one sending the main but it's not. People must understand that Srizbi is rented out to lots of different spammers, so anyone can use it to infect PC's.

Whether spammers are trying to diversify their spam operations with different botnets,
trying to stay off the radar by sending malware from different botnets to confuse researchers or some sort of sharing deal has taken place between the bot herders and their spammer customers, all agree that Srizbi and Rustock are still two separate networks of bots with explicit command and control foundations.

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 15, 2010
It is time for windows board to wake up and lock all system files , only to be opend by getting a licence... more..
March 15, 2010
Help us! Still cannot get Antivirus to update or connect to via browser or ping symantec, avg, mcafee,... more..
March 15, 2010
I'd like to say hi im new here i've been lurking around for the past few weeks and finally decided to... more..
more comments..
rss
Home > Identity Theft > Srizbi and Rustock; Rivals or Siblings?