31.07.2015 Views

Download

Download

Download

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

MytobThe Mytob bot was discovered in February 2005.The bot is characterized as being a hybridsince it used source code from My Doom for the e-mail mass mailing portion of code andbot IRC C&C functionality. Note that “tob” is “bot” backwards.Mytob uses social engineering and spoofed e-mail addresses, carries its own SMTPclient, and has C&C capabilities similar to Spybot.Capabilities Coming to a Bot Near YouThis section contains brief descriptions of a few new bot components:Botnets: A Call to Action • Chapter 1 15■■■GpCoder A potential bot component that encrypts a user’s files then leaves amessage to the user on how they can buy the decoder. Current versions can bedecrypted by A/V vendor “fix” tools, but if later versions use stronger encryptionthe potential for damage could be big.Serv-U Installed on botclients, the Serv-U ftp server enables botherders to storestolen movies, software, games, and illegal material (for example, child pornography)on their botnets and serve the data upon demand. Using other software, the Serv-Uftp server appears to be Windows Explorer in Task Manager.The data is beingstored in hidden directories that can’t be reached using Windows.SPIM Spam for Instant Messaging. Bots have now been used to send phishingattacks and links to Web sites that upload malicious code to your PC.An example SPIM message:ATTENTION...Windows.has.found.55.Critical.System.Errors...To fix the errors please do the following:..1 <strong>Download</strong> Registry Update from: www.regfixit.com.2 Install Registry Update3 Run Registry Update.4 Reboot your computerFAILURE TO ACT NOW MAY LEAD TO SYSTEM FAILURE!McAfee’s Site Advisor flags the aforementioned site as one that uploads malicious code.Cases in the NewsWith bot authors publishing so many variants, you would think that it might be easier toeventually catch some of these people. And you would be right.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!