Waledac Botnet Now Completely Offline, Experts Say
Trailrunner7 writes "After Microsoft's actions to take down the Waledac botnet last month, there was some question about whether the operation was much more than a grab for headlines that would have little effect on actual spam levels or malware infections. But more than three weeks after the takedown, researchers say that Waledac has essentially ceased communications and its spam operations have dropped to near zero. One researcher said that Waledac now seems to be abandoned. 'It looks crippled, if not dead,' said Jose Nazario, a senior security researcher at Arbor Networks."
That is not dead which can eternal lie.
And with strange aeons even death may die.
So Microsoft just killed off one of its competators. Now their "security update" messages will be able to get through easier.
Who would win this election: Andrew Weiner vs Andrew Weiner's weiner.
I think everyone knew the answer was, no it will not have an effect on spam levels or malware infections. Oh it succeeded in taking the botnet offline, MS did something real here, but taking just one offline doesn't mean much.
"I use a Mac because I'm just better than you are."
Its dead Jim.
If I were God, wouldn't I protect my churches from acts of me?
I'm finding it hard to believe that MS brought down the behemoth by secretly bringing down those domain names.
On the other hand, maybe the little miscreants that created this botnet actually made the assumption that the domains couldn't be suspended. That still brings up the question, how long can this court-ordered suspension really last? Indefinitely is not a definite answer.
Going to go check my spam folder now... maybe it's got less crap in it now.
My ZooLoo
Waledac will be back... as SkyNet.
Main characters seldom die off, not unless they've moved to a new show. So, figure he'll be back, meaner and badder than ever. It's just too much like taking candy from a baby not to.
I think it was "Zed's dead, Baby, Zed's dead"
The bloody botnet operator's and malware author's ? Isn't this like fighting the symptoms instead of the cause ?
It's restin'.
our botnet is just down for a couple of hours due to maintainance. we'll back online soon and kindly apologize for any inconvenience caused.
Just like it's maker if he made contracts with the wrong people.
Cwm, fjord-bank glyphs vext quiz
Capt.DrumkenBum (1173011) said: Its dead Jim.
snikulin (889460) said: I think it was "Zed's dead, Baby, Zed's dead"
You guys should swap UIDs.
Set your phasers on "funky"!
Oh, this must be why my spam messages went from over 300 per day, down to just around 20-30 in the past couple weeks. Here I thought Gmail improved their spam filters.
ATTN.: sir,
.He told me he deposited a trunk box containing us$25.5m with a security in EAUROPE(UK) all in the aim of retrieving it himself before he was finally killed before the christmas. According to him
the content of the box was registered as government classified papers with his influence and was moved out of my country through diplomatic courrier.He wanted to safeguard the funds for foriegn investment after his
retirement before he was killed.
I got your contact through email business directory and decided to send my proposal to you. I am MUYIWA IGE the first son of the late chief BOLA IGE,the attorney general of the fedeal rebulic of Nigeria who was killed by hired assasin on the 23rd of december 2001 by an unidentified gun men believed to be link to our government of which it is a daily case going on in my country's dailies now.
Two months ago he was attempted to be murdered but unfortunately God speared his life for us.It was then he had to reveal some vital informations as regards his life to me before he was finally killed in december. All accounts belonging to my father both local and abroad had been frozen and his investments seized by the government believing in thier false allegation that he made away of $2 billion dollars of (NEPA)national electricity power authority of which i know is just a ploy to eliminate him by the people in power that he is fustrating thier evil intentions through the human right pubic hearing for violation of right and cruelsome killings during the military regime to carry out thier traits to suffer the mases for thier selfish interest instead of the interest of the nation.We are now in a dileman as ou live are in danger till after the investigations.
Two weeks to the christmas holiday in 2001 being on the 4th of december,my dad spoke to me at lenght about life and it realities
In the light of this as the next of kin i am now contacting you a foreigner to assist ME in retrieving the boxes and depositing of the fund into your foreign account hence the need to contact you. I and my mother had agreed to give you 30% of the fund for your assistance and 10% for any expenses you might incur in the course of this transaction, we want to believe that you will not sit on the money when paid into your account. I want you to understand that there is no risk involve as we have worked out modalities for the smooth actualization of this goal. The boxes presently is in a security vault of this company in their offshore office in SPAIN.i will require the following for effecting the documents of claim and identification.:
1] Your driving license to assure us of your person
2] Your private telephone and fax numbers.
I will send the following:
3] The receipt of the ware bill used in sending the boxes
4] The deposit certificate
All these will be send through YOUR FAX NUMBER then you will proceed for claim after due schedule with them.you
I wish to state here that we are left with nothing as we survive by the grace of God. I hope you understand our predicament so as to save me and my family from hopeless future (S.O.S.)
All contacts for now should be through my personal email address for security reasons.
Waiting your urgent response.
Best regards,
MUYIWA IGE.
I'll never bemoan a success in the victory against cybercrime, but it would be nice if one of these announcements came against a botnet that was still relevant and sending out large amounts of spam like Rustock. When the trumpet was sounded by Microsoft about the death of the Storm botnet, it was about 18 months since it had been highly relevant.
As others have said, shutting down individual botnets doesn't have long-term effects. That lesson was learned when McColo was taken offline.
... it's pining for the fjords!
There is a war going on for your mind.
Now they want to kill spam and viruses. Sheesh. I thought they were all about generating jobs, not killing them. If they keep killing botnets and viruses and stop creating widely-deployed web browsers and operating systems with no reliability and security, who's going to keep paying us to keep fixing these things all the time? Tell them to bring back win98 and the com2: irq conflicted dial-up modems. That was great, generated tech calls all day long. At least we have usb, fast-mutating, and browser-installed viruses now.
Build your own energy sources from scratch. http://otherpower.com/
The only reason this worked is that the botnet was poorly designed. It relied on at least one of the command and control servers being available. If they all get taken down at the same time you destroy the botnet. This is not how most other botnets work, this is not a tactic that worked against this specific botnet and will not work against other botnets.
Other botnets generate new domain names fairly regularly. All the botnet controller needs to do is register one of those domains before it is generated. Good luck getting a court order to ban all the generated domains for the next few years.
FROM: MUYIWA IGE
.He told me he deposited a trunk
box containing us$25.5m with a security in EAUROPE(UK)
all in the aim of retrieving it himself before he was
finally killed before the christmas. According to him
the content of the box was registered as government
classified papers with his influence and was moved out
of my country through diplomatic courrier.He wanted to
safeguard the funds for foriegn investment after his
retirement before he was killed.
ATTN.: sir,
I got your contact through email business directory and decided to send my proposal to you. I am MUYIWA IGE the first son of the late chief BOLA IGE,the attorney general of th e fedeal rebulic of Nigeria who was killed by hired assasin on the 23rd of december 2001 by an unidentified gun men believed to be link to our government of which it is a daily case going on in my country;s dailies now.
Two months ago he was attempted to be murdered but unfortunately God speared his life for us.It was then he had to reveal some vital informations as regards his life to me before he was finally killed in december. All accounts belonging to my father both local and abroad had been frozen and his investments seized by the government believing in thier false allegation that he made away of $2 billion dollars of (NEPA)national electricity power authority of which i know is just a ploy to eliminate him by the people in power that he is fustrating thier evil intentions through the human right pubic hearing for violation of right and cruelsome killings during the military regime to carry out thier traits to suffer the mases for thier selfish interest instead of the interest of the nation.We are now in a dileman as ou live are in danger till after the investigations.
Two weeks to the christmas holiday in 2001 being on the 4th of december,my dad spoke to me at lenght about life and it realities
In the light of this as the next of kin i am now contacting you a foreigner to assist ME in retrieving the boxes and depositing of the fund into your foreign account hence the need to contact you. I and my mother had agreed to give you 30% of the fund for your assistance and 10% for any expenses you might incur in the course of this transaction, we want to believe that you will not sit on the money when paid into your account. I want you to understand that there is no risk involve as we have worked out modalities for the smooth actualization of this goal. The boxes presently is in a security vault of this company in their offshore office in SPAIN.i will require the following for effecting the documents of claim and identification.:
1] Your driving license to assure us of your person
2] Your private telephone and fax numbers.
I will send the following:
3] The receipt of the ware bill used in sending the boxes
4] The deposit certificate
All these will be send through YOUR FAX NUMBER then you will proceed for claim after due schedule with them.you
I wish to state here that we are left with nothing as we survive by the grace of God. I hope you understand our predicament so as to save me and my family from hopeless future (S.O.S.)
All contacts for now should be through my personal email address for security reasons.
Waiting your urgent response.
Best regards,
MUYIWA IGE.
MY PERSONAL EMAIL
ADDRESS(muyiige@mail.com)ALTERNATIVE RESPONSE
The spammers using this botnet most likely cut it off to work on enlarging another.
Why waste time(read money) repairing something broken when the new, harder to kill version does the same thing in the same time-cost?
Other botnets generate new domain names fairly regularly. All the botnet controller needs to do is register one of those domains before it is generated. Good luck getting a court order to ban all the generated domains for the next few years.
No problem. Individual court orders should do the trick. After seeing 200+ ISPs going through depeering hell, Hosting providers will be a lot more careful who they let have a server. Of course, this is a less than ideal scenario for IT folk in general (especially because it puts the onus on hosting providers to monitor traffic), but it might be effective.
Dear Sir or Madaam:
My name is John Waledac. I am the designer and owner of a profitable spam company. Recently, my company has fallen upon hard times as several of our servers have broken down. We have the funds to replace these servers, but it will take several weeks to transfer the funds from our bank in Nigeria. This delay could cost our company thousands of dollars. This is where you come in. I am seeking investors to loan up to $100,000 for the purchase of new servers. When the funds from Nigeria arrive you will be reembursed with 20% interest. This whole process should be fully accomplished within 25-30 working days, further information will be given to you as soon as I receive your positive response via e-mail or telephone. If you are interest urgently reach me through the above stated email,telephone numbers to enable me give you the full details of this transaction and how it is going to work out. If you decide to invest I need you to send me
1. Your Name and Address
2. Your Telephone Number
3. The Amount You Wish to Invest
4. Your bank account number
Sincerely,
John Waledac
Tel:011234-8035647626.
NB: Kindly send further correspondence to jwaledac@fastermail.com
Sure my spam folder always has shit in it, but really none of it ever makes it through Googles spam filters into my inbox.
Morpheus, God of Dreams.
The fat lady is singing.
Tell me you took down the Zeus botnet, then I will say you accomplished something, but of course the least dangerous botnet will be easier to take down, even the script kiddies know to cycle their botnets, and out with the old in with the new. So what if the botnet you took down is old and degenerate and has almost no spam left attached to its name, you can still make a name for yourself by taking it down, right?
I just checked spamcop stats page, we had a few quiet days but everything is back to normal, thanks for coming.
I prefer Classic Slashdot.