Pushdo Trojan Infects 11,000 Systems In 24 Hours
An anonymous reader writes Bitdefender has discovered that a new variant of the Trojan component, Pushdo, has emerged. 77 machines have been infected in the UK via the botnet in the past 24 hours, with more than 11,000 infections reported worldwide in the same period. The countries most affected so far by the Pushdo variant are India, Vietnam and Turkey. Since Pushdo has resurfaced, the public and private keys used to protect the communication between the bots and the Command and Control Servers have been changed, but the communication protocol remains the same.
What operating system does this software run on?
I just don't understand how this is worth a headline on Slashdot. The targeted population centers alone are so vast and connected that 11k is a pittance. The common flu probably has a greater influence there.
All rites reversed 2010
The way the article describes Pushdo, it sounds a lot like ZeuS - they use practically the same methods of operation (DGA to generate random domain names, fast-flux to stop anyone shutting down the C&C servers) and it seems that like ZeuS, Pushdo started from an initial codebase and was changed multiple times after being shut down.
Just shutdown No-IP servers. That should fix it.
"Somebody has to do something. It's just incredibly pathetic it has to be us."
--- Jerry Garcia
North Korea is least affected, due to their "Don't let anyone have computers, well they don't have electricity anyway" security policy.
Gamingmuseum.com: Give your 3D accelerator a rest.
Is this distributed by E-Mail, a bug in Windows? IE, Firefox etc.?
Harrison's Postulate - "For every action there is an equal and opposite criticism"
Just use Linux.
aaaaaaa
OR any users of my program (which adds more speed, security, reliability, & even anonymity PLUS shores up DNS redirect security issues (bonus)):
APK Hosts File Engine 9.0++ 32/64-bit:
http://start64.com/index.php?o...
(Details of benefits in link)
Summary:
---
A.) Hosts do more than:
1.) AdBlock ("souled-out" 2 Google/Crippled by default)
2.) Ghostery (Advertiser owned) - "Fox guards henhouse"
3.) Request Policy -> http://yro.slashdot.org/commen...
B.) Hosts add reliability vs. downed/redirected dns (& overcome redirects on sites, /. beta as an example).
C.) Hosts secure vs. malicious domains too -> http://tech.slashdot.org/comme... w/ less added "moving parts" complexity/room 4 breakdown,
D.) Hosts files yield more:
1.) Speed (adblock & hardcodes fav sites - faster than remote dns)
2.) Security (vs. malicious domains serving malcontent + block spam/phish & trackers)
3.) Reliability (vs. downed or Kaminsky redirect vulnerable dns, 99% = unpatched vs. it & worst @ isp level + weak vs Fastflux + dynamic dns botnets)
4.) Anonymity (vs. dns request logs + dnsbl's).
---
* Hosts do more w/ less (1 file) @ faster levels (ring 0) vs redundant inefficient addons (slowing slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ os, & 1st net resolver queried w\ 45++ yrs.of optimization).
* Addons = more complex + slow browsers in message passing (use a few concurrently & see) & are nullified by native browser methods - It's how Clarityray is destroying Adblock.
* Addons slowup slower usermode browsers layering on more - & bloat RAM consumption too + hugely excessive cpu use (4++gb extra in FireFox https://blog.mozilla.org/nneth...)
Work w/ a native kernelmode part - hosts files (An integrated part of the ip stack)
APK
P.S.=> "The premise is quite simple: Take something designed by nature & reprogram it to make it work for the body rather than against it..." - Dr. Alice Krippen: "I am legend"
...apk
This - FastFlux &/or Dynamic DNS utilizing botnets FAIL completely against it (+ can't communicate "back to HQ" either even IF/WHEN you are infested) -> http://it.slashdot.org/comment...
Courtesy of "yours truly", gratis (no strings attached ala tracking, malicious code, etc., for absolute 100% free) - why? It's doing the right thing by myself, others, & just in general, since I could - that's good enough reason for me & IF I am 'wrong'? Then, I don't WANT to be "right"... pretty simple.
It just works!
Simply since hosts files use host-domain names to operate blocking off such threats from even getting to you in the 1st place - ala "what you can't touch, can't touch you" allowing YOU complete local FAST control of that as well - bonus!
(Yes, they work, & even vs. massively dynamically generated ones, which sources in the security community supply & yes, that I add (or my 12 sources in the security community to), ala GarWarner from Malcovery supplying them freely as he did to all of us here on /. just the other day, regarding GameOver + CryptoLocker even if you follow his links deep enough -> http://it.slashdot.org/comment...
* I thanked and yes, COMPLIMENTED him on his fine efforts, hard work, & knowledge as well - he deserves it.
I use ZeusTracker as a source for that, since it has many variants (GameOver, IceIX, Citadel, & of course "base ZBot") - per that article's subject matter.
APK
P.S.=> It's all "fine & dandy" that the US law enforcement tries protecting us vs. that (by mandating ISP's remove those domains from DNS servers resolving them, OR, even taking over servers that are C&C in the US, or routing them thru THEIR servers for monitoring them for FULL shutdown) here in the United States, but I don't take chances & add them to my hosts file via my program, which of course, can help OTHERS AROUND THE PLANET not afforded such protections by their authorities, as well... apk
This does the trick for you, on YOUR system locally, giving YOU complete control too -> http://it.slashdot.org/comment...
* It just works & especially vs. FastFlux &/or Dynamic DNS using botnets (the most advanced + dangerous design there is, but they FAIL vs. hosts files users that populate against their mechanics, totally...)
FACT - & it gets its data for doing so from 12 reputable + reliable sources for it in the security community itself that monitor such threats...
APK
P.S.=> Enjoy - should you elect to use it (it's free, works, & does the job BETTER than any single browser addon under the sun + even shores up DNS redirect issues - bonus!)... apk
To go along with using what I wrote originally in regards to hosts files efficacy vs. FastFlux + DynDNS botnets (& a lot more in the way of malicious threats online + bandwidth sapping advertisements & FAR more) -> http://it.slashdot.org/comment...
APK
P.S.=> May not be "absolutely current" (as to the Domain Generating Algorithm used), but THOSE come out from the security community eventually, ala GarWarner of Malcovery helping us out here on /. the other day in fact, vs. GameOver (a ZBot/Zeus variant) & even CryptoLocker's many, Many, MANY 1,000s of nodes/endpoints + C&C Servers, here:
http://it.slashdot.org/comment...
However - the FINE AVAST ARTICLE from 2013 lists the KEY C&C servers it uses (200++ approximately) here:
http://blog.avast.com/2013/06/...
Thus, you use that data for "chopping it off @ the roots" for commands/instructions to infested enslaved systems, (effectively NULLIFYING it via host-domain name usage which FastFlux &/or Dynamic DNS using botnets ARE dependent on...)
... apk
To go along with using what I wrote originally in regards to hosts files efficacy vs. FastFlux + DynDNS botnets (& a lot more in the way of malicious threats online + bandwidth sapping advertisements & FAR more) -> http://it.slashdot.org/comment...
APK
P.S.=> May not be "absolutely current" (as to the Domain Generating Algorithm used), but THOSE come out from the security community eventually, ala GarWarner of Malcovery helping us out here on /. the other day in fact, vs. GameOver (a ZBot/Zeus variant) & even CryptoLocker's many, Many, MANY 1,000s of nodes/endpoints + C&C Servers, here:
http://it.slashdot.org/comment...
However - the FINE AVAST ARTICLE from 2013 lists the KEY C&C servers it uses (200++ approximately) here:
http://blog.avast.com/2013/06/...
Thus, you use that data for "chopping it off @ the roots" for commands/instructions to infested enslaved systems, (effectively NULLIFYING it via host-domain name usage which FastFlux &/or Dynamic DNS using botnets ARE dependent on...)
... apk
To go along with using what I wrote originally in regards to hosts files efficacy vs. FastFlux + DynDNS botnets (& a lot more in the way of malicious threats online + bandwidth sapping advertisements & FAR more) -> http://it.slashdot.org/comment...
APK
P.S.=> May not be "absolutely current" (as to the Domain Generating Algorithm used), but THOSE come out from the security community eventually, ala GarWarner of Malcovery helping us out here on /. the other day in fact, vs. GameOver (a ZBot/Zeus variant) & even CryptoLocker's many, Many, MANY 1,000s of nodes/endpoints + C&C Servers, here:
http://it.slashdot.org/comment...
However - the FINE AVAST ARTICLE from 2013 lists the KEY C&C servers it uses (200++ approximately) here:
http://blog.avast.com/2013/06/...
Thus, you use that data for "chopping it off @ the roots" for commands/instructions to infested enslaved systems, (effectively NULLIFYING it via host-domain name usage which FastFlux &/or Dynamic DNS using botnets ARE dependent on...)
... apk
To justify attacking it as much as Windows on PC desktops - period!
See (& you'd KNOW this if you weren't some newbie): The MORE an OS is used, on ANY given hardware platform, the more it will be attacked - fact! I've seen it decades before, on DOS, & that's how I KNOW that is how it really is...
What shows that for Linux though? Android!
ANDROID's being exploited DAILY & yes, it IS a Linux (using a Linux core, which surely isn't MacOS X/IOS or Windows of any type either) variant.
APK
P.S.=> You noob shill FOOLS make me laugh with your utter b.s. & yes, you ARE "noobz" with your nigh-constant b.s. FUD you spouted here of "Linux = Secure & Windows != Secure" crap, & for coming up on 2++ decades here on /. too, no less is FALLING APART rapidly!
How/why? See above!
Yes - Your "precious Linux" IS not invulnerable, period!
Which yes, as far as Linux goes? Yes, I like & use(d) it too - but I went back to Windows due to better hardware driver availability + more programs for my purposes that are available on Windows but NOT on Linux!
(However I do *NOT* like your bullshit you all spouted here which my proofs above toss into the shitter easily along with "your kind" with it as well)
Yes: Linux IS being attacked, HUGELY, & where it "rules" on smartphones as the hardware platform (unfortunately, with a STUPID Java/Dalvik front-end that opens it up MORE to attack & exploit, which it has been because of that & it is NOT "invulnerable", proof's above)... apk