drone armies C&C report - Jan/2005

From: Gadi Evron (gadi_at_tehila.gov.il)
Date: 01/30/05

  • Next message: 3APA3A: "Re[2]: SECURITY.NNOV: Multiple applications fd_set structure bitmap array index overflow"
    Date: Sun, 30 Jan 2005 13:43:25 +0200
    To: bugtraq@securityfocus.com
    
    

    Below is a periodic public report from the drone armies / botnets
    research and mitigation mailing list.
    For this report it should be noted that we base our analysis on the data
    we have accumulated from various sources.

    According to our incomplete analysis of information we have thus far, we
    now publish two reports.

    The ISP's that are most often plagued with botnet C&C's (command &
    control) are, by the order listed:
    ----------------------------------
    1. AS21844 THEPL-1 THE PLANET
    2. AS6517 YIPS Yipes Communications Inc
    3. AS21840 SAGONE Sago Networks
    4. AS4766 KIXS-AS-KR Korea Telecom
    5. AS5731 ATTW AT&T WorldNet Services
    6. AS25761 STAMIN-2 Staminus Communicatio
    7. AS30083 SERVE-6 Server4You Inc.

    * We would gladly like to establish a trusted relationship with
       these and any organizations to help them in the future.

    The Trojan horses most used in botnets:
    ---------------------------------------
    1. Korgobot.
    2. SpyBot.
    3. Optix Pro.
    4. rBot.
    5. Other SpyBot variants and strains (AgoBot, PhatBot, actual SDbots,
        etc.).

    Contact information:
    Hank Nussbacher <hank@mail.iucc.ac.il>
    Gadi Evron (as specified below)

    -- 
    Gadi Evron,
    Information Security Manager, Project Tehila -
    Israeli Government Internet Security.
    Ministry of Finance, Israel.
    gadi@tehila.gov.il
    gadi@CERT.gov.il
    Office: +972-2-5317890
    Fax: +972-2-5317801
    http://www.tehila.gov.il
    The opinions, views, facts or anything else expressed in this email
    message are not necessarily those of the Israeli Government.
    

  • Next message: 3APA3A: "Re[2]: SECURITY.NNOV: Multiple applications fd_set structure bitmap array index overflow"

    Relevant Pages

    • drone armies C&C report - Feb/2005
      ... Below is a periodic public report from the drone armies / botnets ... For this report it should be noted that we base our analysis on the data ... Information Security Manager, Project Tehila - ... The opinions, views, facts or anything else expressed in this email message are not necessarily those of the Israeli Government. ...
      (Bugtraq)
    • drone armies C&C report - May/2005
      ... Below is a periodic public report from the drone armies / botnets ... For this report it should be noted that we base our analysis on the data ... Other SpyBot variants and strains (AgoBot, PhatBot, actual SDbots, ... message are not necessarily those of the Israeli Government. ...
      (Bugtraq)
    • drone armies C&C report - March/2005
      ... Below is a periodic public report from the drone armies / botnets ... For this report it should be noted that we base our analysis on the data ... 25761 STAMINUS-COMM - Staminus Commu 16-20 ... INTERNAP Internap 11-15 ...
      (Bugtraq)
    • Military Setbacks Have Israel in a State of Soul-Searching
      ... The Israeli government has ... U.S. and friendly nation laws prohibit fully ... with our laws this report cannot be provided in ... Military News and Information Editor ...
      (soc.culture.israel)
    • Military Setbacks Have Israel in a State of Soul-Searching
      ... The Israeli government has ... U.S. and friendly nation laws prohibit fully ... with our laws this report cannot be provided in ... Military News and Information Editor ...
      (talk.politics.mideast)