Latest Comments
"I too have been a labor voter for many years and will not be voting for them again. The ..."
by maxt | Feb 9, 2010 7:56 PM
 
"I’ve just had a user receive a rehashed version of this with an attached html file containing a ..."
by Owen Lutz | Feb 9, 2010 6:01 PM
 
"hi"
by manish kumar | Feb 9, 2010 4:27 PM
 
"Hey 'hey con-roy' ... from Google Australia's head of policy Iarla Flynn"We don't believe that ..."
by Keep it real | Feb 9, 2010 3:33 PM
 
"@penno Off-site storage is a good solution unless you have some decent backup software to ..."
by Charmgene | Feb 9, 2010 2:36 PM

Malicious server used to propagate Zbot shut down

  • Email a Friend
  • Print Page
Malicious server used to propagate Zbot shut down
By Angela Moscaritolo
Jul 2, 2009 10:10 AM | 1 Comment
Tags: ZBot | malicious | server | botnet | Cayman | Islands | trojan | FTP | credentials | infected
A criminal operation has been halted by the shutdown of a malicious server in the Cayman Islands, but the attackers are likely to be looking for a new home.

Prevx researchers recently discovered a site where the trojan Zbot had uploaded the FTP login credentials from more than 68,000 websites, including companies such as Bank of America, BBC, and Symantec. Since then, more than 20,000 additional stolen FTP credentials were used to inject malicious scripts on those sites, Jacques Erasmus, director of research at Prevx, told SCMagazineUS.com. But the attacker's server, based in the Cayman Islands, was shut down on earlier this week.

Up until last week, when visiting a compromised website, users were being infected (by means of a drive-by download) with Zbot, a trojan that captures keystrokes to obtains login credentials and credit card information, Erasmus said. Once a user was infected, the trojan harvested FTP credentials and sent them back to the attack server.

This week, however, a second component of the attack was activated -- the infected computers began “calling home”: communicating with the attack server in the Cayman Islands. When they began calling home, FTP credentials were pushed to the infected computers, with instructions to attempt logging on to sites associated with the credentials (that is, websites whose FTP credentials were stolen) and -- if successful -- to inject them with malicious scripts.

“Since Monday it started infecting a lot of websites, embedding script in the websites,” Erasmus said. “Anyone who visits one of these websites will also get infected.”

One infected machine attempted to inject malicious scripts into 85 different domains in a five-minute period, Erasmus said.

He said that because the controlling server in the Cayman Islands is currently “dead”, no additional websites are being injected with malicious scripts. What remains is a lot of compromised websites that are now further propagating the Zbot trojan. Erasmus said that the big-name websites whose FTP credentials were stolen have all been contacted and those companies canceled the accounts that were harvested. 

Though the attack server is currently down, it looks like those responsible for the threat are trying to move their operations to a different server, Erasmus said.

“Similar servers are popping up and we are trying to figure out if this is the same group,” Erasmus said.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
The 6.0 version of Evidence Eliminator by Robinhood software on its website contains the Zbot trojan and is not detected until after install. Steer clear of it.
SC Magazine - comments icon Posted by nunyaOct 7, 2009 2:36 AM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers