<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; bot</title>
	<atom:link href="http://www.megapanzer.com/tag/bot/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.megapanzer.com</link>
	<description></description>
	<lastBuildDate>Fri, 10 Sep 2010 13:23:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Conficker data highlights infected networks</title>
		<link>http://www.megapanzer.com/2009/12/16/conficker-data-highlights-infected-networks/</link>
		<comments>http://www.megapanzer.com/2009/12/16/conficker-data-highlights-infected-networks/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 21:51:15 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3217</guid>
		<description><![CDATA[On Wednesday, the ShadowServer Foundation took the wraps off a revamped statistics page, showing how far the three main variants of Conficker have spread and the degree to which the world&#8217;s networks are infected. More than 12,000 networks, as represented by their autonomous system numbers (ASNs), show signs of infection by Conficker. The ShadowServer Foundation [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="newspaper" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" />On Wednesday, the ShadowServer Foundation took the wraps off a revamped statistics page, showing how far the three main variants of Conficker have spread and the degree to which the world&#8217;s networks are infected. More than 12,000 networks, as represented by their autonomous system numbers (ASNs), show signs of infection by Conficker. The ShadowServer Foundation limited their displayed data to the top 500 networks.</p>
<p>&#8220;Our major goal is to show how far and wide Conficker has spread and where Conficker really has a foothold,&#8221; said André DiMino, founder and director of the ShadowServer Foundation.</p>
<p>The team of volunteer researchers, which helped to establish the Conficker Working Group early this year, collects data from its member organizations.</p>
<p>The ShadowServer data groups Conficker into two classes. Conficker A+B consists of the first two variants of the program, which attempt to spread automatically. Conficker C, a variant that appeared in March, has no way to propagate unless it is updated. Overall, the number Internet addresses showing signs of infection by Conficker A+B are increasing, while signs of Conficker C infection are decreasing.</p>
<p>Read more <a href="http://www.securityfocus.com/news/11568" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/12/16/conficker-data-highlights-infected-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 botnets and their impact</title>
		<link>http://www.megapanzer.com/2009/12/09/top-10-botnets-and-their-impact/</link>
		<comments>http://www.megapanzer.com/2009/12/09/top-10-botnets-and-their-impact/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 17:20:40 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3192</guid>
		<description><![CDATA[Every day, approximately 89.5 billion unsolicited messages (i.e. spam) are sent by computers that have been compromised and are part of a botnet. Botnets &#8211; apart from inundating out inboxes with spam &#8211; can also be used for ulterior purposes such as executing DDoS attacks or hosting websites, so understanding the &#8220;modus operandi&#8221; and size [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="newspaper" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" />Every day, approximately 89.5 billion unsolicited messages (i.e. spam) are sent by computers that have been compromised and are part of a <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1307" title="Glossary: Botnet" target="_blank">botnet</a>.</p>
<p><a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1307" title="Glossary: Botnet" target="_blank">Botnets</a> &#8211; apart from inundating out inboxes with spam &#8211; can also be used for ulterior purposes such as executing DDoS attacks or hosting websites, so understanding the &#8220;modus operandi&#8221; and size behind the well-known names is a good idea.</p>
<p>Message Labs&#8217; list of top 10 <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1307" title="Glossary: Botnet" target="_blank">botnets</a> in 2009 reads like this:</p>
<p><strong>Rustock</strong><br />
Rustock frequently sends spam at full capacity for short periods, and then ceases its activity often for days at a time. Between August and September 2009, it controlled between 1.3 million to 2 million bots.</p>
<p>Rustock had accounted for approximately 10-20% of all spam for much of the year, but by the end of 2009 it had increased its dominance and stabilized its output to approximately 18% of all spam. By the end of 2009, Rustock was mostly sending pharmaceutical and medical spam.</p>
<p><strong>Cutwail</strong><br />
Cutwail consisted of 1 million to 1.5 million bots throughout the year, and was responsible for 17% of all spam.</p>
<p>It was responsible for the surge in Bredolab <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1210" title="Glossary: Malware" target="_blank">malware</a>, spoofed greetings card emails containing malicious hyperlinks, <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1236" title="Glossary: Phishing" target="_blank">phishing</a> activities, pharmaceutical spam and spam peddling counterfeit watches.</p>
<p>Read full article <a href="http://www.net-security.org/secworld.php?id=8599" target="_blank">here</a>.</p></glossarycode></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/12/09/top-10-botnets-and-their-impact/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Realmbot</title>
		<link>http://www.megapanzer.com/2009/12/04/realmbot/</link>
		<comments>http://www.megapanzer.com/2009/12/04/realmbot/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 19:21:08 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Bot sources]]></category>
		<category><![CDATA[RAT sources]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[irc]]></category>
		<category><![CDATA[REalmbot]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3178</guid>
		<description><![CDATA[&#160; &#160; &#160; Name Realmbot &#160; Type RAT, Bot &#160; &#160; Author Unknown &#160; &#160; Written in C/C++ &#160; &#160; Description This is a variant of the REalmbot created by Lindem in 2006. Also here many of the typical bot functions were implemented. Services control, user control, process control, key logger (in a rather unelegant [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%">&nbsp;</td>
<td width="50%">&nbsp;</td>
<td width="20%">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Name</strong></td>
<td>Realmbot</td>
<td rowspan="5">
<img src="http://www.megapanzer.com/wp-content/uploads/trojan_horse.jpeg" alt="worm" title="worm" width="100" height="96" class="alignright size-full wp-image-2132" />
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Type</strong></td>
<td>RAT, Bot</td>
<td>
&nbsp;
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Author</strong></td>
<td>Unknown</td>
<td>
&nbsp;
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Written in</strong></td>
<td>C/C++</td>
<td>&nbsp;</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong></td>
<td colspan="2">
This is a variant of the REalmbot created by Lindem in 2006. Also here many of the typical bot functions were implemented. <strong>Services control, user control, process control, key logger</strong> (in a rather unelegant way), an <strong>FTP and HTTP server, port redirection</strong>, etc. The structure is a little chaotic. Reading through the code is rather cumbersome.
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Questions</strong></td>
<td colspan="2">In case you have a question just register at the <a href="http://www.megapanzer.com/bbpress">Megapanzer forum</a> and leave an entry in the according board. Your question will be answerd as soon as possible.</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong></td>
<td colspan="2"><a href="http://www.megapanzer.com/wp-content/uploads/realmbot.zip">Source</a></td>
</tr>
</tbody>
</table>
<p><br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/12/04/realmbot/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Economics of Botnets</title>
		<link>http://www.megapanzer.com/2009/11/27/the-economics-of-botnets/</link>
		<comments>http://www.megapanzer.com/2009/11/27/the-economics-of-botnets/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 17:31:03 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Reading material]]></category>
		<category><![CDATA[Stuff]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[click fraud]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3139</guid>
		<description><![CDATA[Nice article about botnets, click fraud and spamming. You can find the original article (written by Yury Namestnikov) on www.viruslist.com. The Economics of Botnets In the past ten years, botnets have evolved from small networks of a dozen PCs controlled from a single C&#038;C (command and control center) into sophisticated distributed systems comprising millions of [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/books-150x150.jpg" alt="books" title="books" width="75" height="75" class="alignright size-thumbnail wp-image-2238" />Nice article about botnets, click fraud and spamming.<br />
You can find the original article (written by Yury Namestnikov) on <a href="http://www.viruslist.com/" target="_blank">www.viruslist.com</a>.</p>
<p>
<strong>The Economics of Botnets</strong></p>
<p>In the past ten years, botnets have evolved from small networks of a dozen PCs controlled from a single C&#038;C (command and control center) into sophisticated distributed systems comprising millions of computers with decentralized control. Why are these enormous zombie networks created? The answer can be given in a single word: money.</p>
<p>A botnet, or zombie network, is a network of computers infected with a malicious program that allows cybercriminals to control the infected machines remotely without the users’ knowledge. Zombie networks have become a source of income for entire groups of cybercriminals. The invariably low cost of maintaining a botnet and the ever diminishing degree of knowledge required to manage one are conducive to growth in popularity and, consequently, the number of botnets.<br />
<span id="more-3139"></span><br />
So how does one start? What does a cybercriminal in need of a botnet do? There are many possibilities, depending on the criminal’s skills. Unfortunately, those who decide to set up a botnet from scratch will have no difficulty finding instructions on the Internet.<br />
<br />
You can simply create a new zombie network. This involves infecting computers with a special program called a bot. Bots are malicious programs that unite compromised computers into botnets. If someone who wants to start a ‘business’ has no programming skills, there are plenty of ‘bot for sale’ offers on forums. Obfuscation and encryption of these programs’ code can also be ordered in the same way in order to protect them from detection by antivirus tools. Another option is to steal an existing botnet.<br />
<br />
The cybercriminal’s next step is to infect user machines with bot malware. This is done by sending spam, posting messages on user forums and social networks, or via drive-by downloads. Alternatively, the bot itself can include self-replication functionality, like viruses and worms.<br />
<br />
Various social engineering techniques are used when ordering spam mailings or posting messages on user forums and social networks in order to cause potential victims to install a bot. For example, users can be offered an interesting video to view, which requires downloading a special codec. Of course, the user won’t be able to watch the video after downloading and launching the file. In fact, the user will probably not notice any changes at all, but at the same time the computer will be infected. As a result, the computer will become an obedient servant at the beck and call of the botnet owner without the user being any the wiser.<br />
<br />
Another widely used method involves covertly downloading malware via drive-by-downloads. This method is based on taking advantage of various vulnerabilities in applications, primarily popular browsers, to download malware to the computer when the user visits an infected web page. This is done with special programs called exploits, which use vulnerabilities not only to covertly download, but also to run a malicious program without the user’s knowledge. If the attack is successful, the user will not even suspect that there is something wrong with the computer. This method of distributing malicious software is particularly dangerous, since tens of thousands of people get infected when a popular web resource is compromised.<br />
</p>
<table>
<tr>
<td>
<a href="http://www.megapanzer.com/wp-content/uploads/botnet_11.png" target="_blank"><br />
<img src="http://www.megapanzer.com/wp-content/uploads/botnet_11-1024x609.png" alt="botnet_1" title="botnet_1" width="512" height="305" class="alignleft size-large wp-image-3161" /></a>
</td>
</tr>
<tr>
<td>
<strong>Figure 1: A snare for users (a fake Youtube post)</strong>
</td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
</table>
<p>A bot can be designed to include the feature of self-propagation in computer networks, e.g., by infecting all the executable files it can access or by scanning the network for vulnerable computers and infecting them. The Virus.Win32.Virut and Net-Worm.Win32.Kido families are examples of such bots. The former is a polymorphic file infector, the latter a network worm. It is hard to overestimate the effectiveness of this approach: today, the zombie network created by Kido is the world’s largest.<br />
<br />
The botnet owner can control unsuspecting users’ infected computers via the botnet’s command &#038; control center, by connecting to bots via an IRC channel, a web connection or any other available means. It is sufficient to unite a few dozen machines into a network for the botnet to start making money for its owner. The income is directly proportional to the zombie network’s stability and growth rate.</p>
<p><strong>How botnet owners make money</strong><br />
<br />
So how do botnet owners make money with infected computers? There are several major sources of income: DDoS attacks, theft of confidential information, spam, phishing, SEO spam, click fraud and distribution of adware and malicious programs. It should be noted that, if chosen, any of these sources can provide a cybercriminal with a good income. But why choose? A botnet can perform all of these activities… at the same time!<br />
</p>
<table>
<tr>
<td>
<a href="http://www.megapanzer.com/wp-content/uploads/botnet_21.png" target="_blank"><br />
<img src="http://www.megapanzer.com/wp-content/uploads/botnet_21.png" alt="botnet_2" title="botnet_2" width="493" height="277" class="alignright size-full wp-image-3160" /></a>
</td>
</tr>
<tr>
<td>
<strong>Figure 2: The ‘botnet business’</strong>
</td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
</table>
<p><strong>DDoS attacks</strong><br />
<br />
Many researchers believe that even the earliest botnets provided DDoS functionality. A DDoS attack is an attack on a computer system which aims to force the system into denial of service, when it can no longer receive and process requests from legitimate users. One of the most common attack methods involves sending numerous requests to the victim computer, leading to denial of service if the computer under attack has insufficient resources to process all incoming requests. DDoS attacks are a potent weapon for hackers and botnets are an ideal tool for carrying out such attacks. DDoS attacks can be used as a tool for unfair competition or be manifestations of cyberterrorism.<br />
<br />
A botnet owner can render services to any unscrupulous entrepreneur by organizing a DDoS attack on his competitor’s website. The competitor’s website will be down due to the stress caused by the attack and the cybercriminal will receive a modest (or not-so-modest) reward. Botnet owners themselves can use DDoS attacks in the same way to extort money from large companies. Companies often choose to give in to cybercriminals’ demands because dealing with the consequences of successful DDoS attacks is even more expensive. In January 2009, an attack on godaddy.com, a major web hosting provider, resulted in several thousand websites hosted on the company’s web servers being inaccessible for almost 24 hours. What was it, an illegal move by another popular hosting provider in the combat for a place in the sun, or was Go Daddy blackmailed by cybercriminals? We think that both scenarios are quite likely. Incidentally, the same hosting provider experienced a similar attack in November 2005, but then the service was unavailable for only an hour. The new attack was much more powerful, primarily due to the growth of botnets.<br />
<br />
In February 2007, a series of attacks was conducted targeting the root name servers, on which the entire Internet depends for normal operation. It is unlikely that the purpose of the attacks was to crash the Internet, since zombie networks cannot function without the Internet. It is more likely that this was a demonstration of the power and capabilities of zombie networks.<br />
<br />
Adverts for organizing DDoS attacks are openly displayed on many user forums devoted to the relevant topics. As for the price tag, it can range from $50 to several thousand dollars for 24-hour continuous operation of a botnet carrying out a DDoS attack. The price range makes sense. The task of stopping the sales of a modest unprotected online store for one day can be tackled by a relatively small botnet (about a thousand computers), and will cost the criminal a relatively small amount of money. But if the competitor is a large international company with a well-protected website, the price will be much higher, since a successful DDoS attack will require a much larger number of zombie computers, so the customer will have to pay up.<br />
<br />
According to shadowserver.org, about 190 000 DDoS attacks were carried out in 2008, “earning” cybercriminals about $20 million. Naturally, this estimate does not include revenues from blackmail, which are impossible to assess.</p>
<p><strong>Theft of confidential information</strong><br />
<br />
Confidential information stored on users’ computers will always attract cybercriminals. The most valuable data includes credit card numbers, financial information and passwords to various services, such as email, ftp, IM systems etc. Today’s malicious programs allow criminals to choose the data they want by installing the relevant module on the infected computer.<br />
<br />
Cybercriminals can either sell the information stolen or use it in their own interests. Hundreds of new bank-accounts-for-sale advertisements appear on underground forums every day. The price of an account can range from $1 to $1500. The low minimum price demonstrates that the cybercriminals involved in this business have to reduce their prices due to competition. To make a really significant amount of money, they need a steady inflow of fresh data, which is provided primarily by a stable growth of zombie networks.<br />
<br />
Financial information is of special interest to carders, i.e., people who forge bank cards. The profitability of their operations is well illustrated by the story of a group of Brazilian cybercriminals who were arrested two years ago. They were able to withdraw $4.74 million from bank accounts using information stolen from computers.<br />
<br />
Personal data not directly related to users’ finances are of interest to cybercriminals who forge documents, open fake bank accounts, conduct illegal transactions etc.<br />
<br />
The cost of stolen personal data is directly dependent on the country of its legal owner’s residence. For example, a complete set of data on a US resident costs $5 to 8. EU resident data is particularly valued on the black market and is two or three times more expensive than data for US and Canadian residents. This is because cybercriminals can use this data in any EU country. Worldwide, the average cost of a full package of data on one person is about $7.<br />
<br />
Another type of information collected by botnets is email addresses. Unlike credit card numbers and accounts, numerous email addresses can be harvested from one infected computer. The addresses harvested are then put up for sale, sometimes ‘in bulk’, by megabyte. Spammers are naturally the main buyers. One list of a million email addresses costs $20 to 100, while spammers charge $150 to 200 for a mailing to these same million addresses, making a clear profit.<br />
<br />
Criminals are also interested in user accounts for various paid services and online stores. These are certainly cheaper than bank accounts, but their sale involves lower risk of prosecution by law-enforcement agencies. For example, accounts for Steam, a popular online store, with access to ten games are sold for $7 to 15 per account.<br />
</p>
<table>
<tr>
<td>
<a href="http://www.megapanzer.com/wp-content/uploads/botnet_31.png" target="_blank"><br />
<img src="http://www.megapanzer.com/wp-content/uploads/botnet_31-1024x590.png" alt="botnet_3" title="botnet_3" width="512" height="295" class="alignright size-large wp-image-3159" /></target>
</td>
</tr>
<tr>
<td>
<strong>Figure 3: Forum post offering Steam accounts for sale</strong>
</td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
</table>
<p><strong>Phishing</strong><br />
<br />
New phishing sites are now mass-produced, but they need protection from closure. Zombie networks obligingly provide an implementation of fast flux technology, which allows cybercriminals to change website IP addresses every few minutes without affecting the domain name. This extends the lifetime of phishing sites, making it hard to detect them and take them offline. The idea involves using people’s home computers that are part of a botnet as web servers with phishing content. Fast flux is better than proxy servers at hiding fake websites on the Web.<br />
<br />
Thus, Rock Phish, a well-known phishing ring, works in cooperation with Asprox, a botnet operator. In the middle of last year the ‘Rock Phishers’, who are responsible for half the online phishing attacks and millions of dollars lost by online banking users, upgraded their infrastructure for fast-flux compatibility. This took about five months and everything was done at a highly professional level. Instead of creating their own fast flux network, the phishers acquired a ready-made solution from the owners of the Asprox botnet.<br />
<br />
Cybercriminals, mostly phishers, pay botnet owners $1000 to 2000 per month for hosting fast flux services.<br />
<br />
The average income from phishing is comparable to that from the theft of confidential data using malicious programs and adds up to millions of dollars per year.</p>
<p><strong>Spam</strong><br />
<br />
Millions of spam messages are sent globally every day. Sending unsolicited mail is a major function of today’s botnets. According to Kaspersky Lab data, about 80% of all spam is sent via zombie networks.<br />
<br />
Billions of messages with adverts for Viagra, watch replicas, online casinos etc. are sent from computers of law-abiding users. These messages clutter up communication channels and mailboxes. In this way, hackers expose innocent users’ computers: the sender addresses to which mass mailings are traced are blacklisted by antivirus companies.<br />
<br />
In recent years, the scope of spam services has broadened to include ICQ spam, spam in social networks, user forums and weblogs. This is also an ‘achievement’ of botnet owners: it doesn’t take a lot of effort to add a new module to a bot client in order to open up new horizons for a new business with slogans such as “Spam in Facebook. Cheap”.<br />
<br />
Spam prices vary depending on the target audience and the number of target addresses. The price of a targeted mailing can range from $70 for a few thousand addresses to $1000 for tens of millions.<br />
<br />
In the past year, spammers made about $780,000,000 sending messages. An impressive result for adverts that nobody wants, isn’t it?</p>
<p><strong>Search engine spam</strong><br />
<br />
Another application for botnets is search engine optimization (SEO). Webmasters use SEO in order to improve their websites’ positions in search results, since the higher they get the more visitors will reach the site via search engines.<br />
<br />
Search engines use a number of criteria to assess the relevance of a website. One of the main parameters is the number of links to the site located on other pages or domains. The more such links are found, the higher the search robot rates the site. The words used in the link also affect the rating. For example, the link “buy our computers” will have a greater weight for such queries as “buy a computer”.<br />
<br />
SEO is a flourishing business in itself. Many companies pay lots of money to web masters to bring their websites to top positions in search results. Botnet operators have borrowed some of their techniques and automated the search engine optimization process.<br />
<br />
So if you see lots of links created by an unknown user or even your friend in comments on your favorite live journal entry, don’t be surprised. It only means that somebody has hired the owners of a botnet to promote a web resource. A specially designed program is installed on a zombie computer and leaves comments containing links to the site being promoted on popular resources.<br />
<br />
The average price of illegal SEO spam is about $300 per month.</p>
<p><strong>Adware and malware installation</strong><br />
<br />
Imagine that you are reading your favorite online automobile magazine and suddenly a popup window appears, offering genuine auto accessories for sale. It would seem that there is nothing wrong with that, but you are confident that you didn’t install any software to look for useful (or useless) things. It’s simple: botnet owners have ‘taken care’ of you.<br />
<br />
Many companies that offer online advertising services pay for each installation of their software. As a rule, this is not a lot of money – from 30 cents to $1.50 for each program installed. However, when a cybercriminal has a botnet at his disposal, he can install any software on thousands of computers with a few mouse clicks and earn serious money. J. K. Shiefer, a well-known cybercriminal who was convicted in 2007, ‘earned’ over $14,000 in one month using a botnet of over 250,000 machines to install adware on 10,000 computers.<br />
<br />
Cybercriminals who distribute malicious programs often use the same approach, paying for each installation of their software. This type of cooperation between cybercriminals is called an “affiliate network”. Rates for the installation of software on computers in different countries differ significantly. For example, the average price of installing a malicious program on a thousand computers in China is $3 and in the US $120. This makes sense, since computers of users in developed countries can provide cybercriminals with much more valuable information that can be used to make a lot more money.</p>
<p><strong>Click fraud</strong><br />
<br />
Online advertising agencies that use the PPC (Pay-Per-Click) scheme pay for unique clicks on advertisements. Botnet owners can make significant amounts of money by cheating on such companies.<br />
<br />
An example is the well-known Google AdSense network. Advertisers pay Google for clicks on their ads in the hope that users who visit their sites in this way will buy something from them.<br />
<br />
Google, in its turn, places context-based advertising on the various websites participating in the AdSense program, paying a percentage from each click to website owners. Unfortunately, not all website owners are honest. With a zombie network, a hacker can generate thousands of unique clicks a day – one from each machine to avoid raising Google’s suspicion. Thus the money spent on an advertising campaign makes its way into the hacker’s pockets. Sadly, nobody has been convicted of this kind of fraud so far.<br />
<br />
According to Click Forensics, about 16-17% of all advertising link clicks in 2008 were fake, of which a third was generated by botnets. A simple calculation will show that botnet owners made $33 million ‘for clicks’. Not bad for simple mouse clicks!</p>
<p><strong>Leasing and selling botnets</strong><br />
<br />
Now to the busy botnet owners: for them, Marx’s world-famous formula, “goods – money – goods” translates into “botnet – money – botnet”. Keeping a botnet afloat, ensuring a steady inflow of new zombies, protecting bots from being detected by antivirus products and keeping the C&#038;C from being located requires both financial and time investment from the hacker, so he simply has no time left for sending spam, installing software or stealing and selling information. It is much easier to lease the botnet out or sell it, especially since there is no shortage of those who wish to acquire it.<br />
<br />
The lease of a mail botnet that can send about 1000 messages a minute (with 100 zombie machines working online) brings about $2000 per month. As in the case of leasing, the price of a ready-made botnet depends on the number of infected computers. Ready-made botnets are especially popular on English-speaking user forums. Small botnets of a few hundred bots cost $200 to 700, with an average price amounting to $0.50 per bot. Large botnets cost much more. The Shadow botnet, which was created by a 19-year-old hacker from Holland and included over 100,000 computers, was put on sale for $36,000. This is enough to buy a small house in Spain, but the Brazilian cybercriminal chose the botnet.</p>
<p><strong>Conclusion</strong><br />
<br />
Mind boggling sums make their way into the pockets of people in the botnet business. All sorts of methods are used to combat this business, but at the legislation level it is completely ineffective. Laws on spam and on the development and distribution of malicious programs or on breaking into computer networks are not applied in many countries, even where such laws do exist. Botnet owners or developers who have been prosecuted can be counted on the fingers of two hands. Which is not the case with botnets that are live on the Internet: the number of these has exceeded 3600. In fact, counting functioning botnets is not an easy task, because in addition to a few dozen large botnets that are hard to miss there are numerous smaller zombie networks that are not easy to detect or tell apart.<br />
<br />
At present, the most effective method of combating botnets is close cooperation between antivirus experts, ISPs and law enforcement agencies. Such cooperation has already resulted in the closure of three companies: EstDomains, Atrivo and McColo. Note that the closure of McColo, whose servers hosted command and control centers for several major spam botnets, resulted in a 50% reduction in the amount of spam circulating on the Internet.<br />
<br />
Experts follow the activity of thousands of botnets, and antivirus products detect and destroy bots across the globe, but only law enforcement agencies can stop the command and control centers and catch the cybercriminals, thereby ‘putting out’ botnets for extended periods of time. The closure of McColo only had a short-lived effect: several weeks later spam traffic began to go back to its usual levels. After botnet owners moved their command and control centers to other hosting providers, it was ‘business as usual’ for them again. What is needed is a continual effort rather than occasional inspections. Sadly, chopping off one head of the hydra is not enough!<br />
<br />
Without help from users, combating botnets cannot be effective. It is home computers that make up the lion’s share of the enormous army of bots. Neglecting to stick to simple security rules, such as using antivirus software, using strong account passwords and disabling the AutoPlay feature for removable media, can result in your computer becoming another botnet member, providing cybercriminals with your data and resources. Why help cybercriminals?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/11/27/the-economics-of-botnets/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Four held in crackdown on Austro-German hackers</title>
		<link>http://www.megapanzer.com/2009/11/26/four-held-in-crackdown-on-austro-german-hackers/</link>
		<comments>http://www.megapanzer.com/2009/11/26/four-held-in-crackdown-on-austro-german-hackers/#comments</comments>
		<pubDate>Thu, 26 Nov 2009 05:50:04 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Carding]]></category>
		<category><![CDATA[raid]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3130</guid>
		<description><![CDATA[In raids throughout Germany and Austria, police closed down a web gang which stole private credit-card data and used viruses to create a network of 100,000 robot computers, Germany&#8217;s Federal Crime Office said Wednesday. In Germany, three persons were detained during the Tuesday raids on 46 homes. One was held in Austria. Many computers were [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="newspaper" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" />In raids throughout Germany and Austria, police closed down a web gang which stole private credit-card data and used <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=3302" title="Glossary: Virus" target="_blank">viruses</a> to create a network of 100,000 robot computers, Germany&#8217;s Federal Crime Office said Wednesday.</p>
<p>In Germany, three persons were detained during the Tuesday raids on 46 homes. One was held in Austria. Many computers were seized.</p>
<p>The offenders, aged 15 to 26, knew one another via an internet forum devoted to hacking and hid behind nicknames. Police took a year to infiltrate the forum and gradually uncover their true identities.</p>
<p>The Austria administrator of the forum set up the so-called bot net, in which 100,000 computers, unknown to their owners, were infected with <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=3302" title="Glossary: Virus" target="_blank">virus</a> software and were doing his bidding, providing him with both massive networked computing power and secrets.</p>
<p>The forum named itself the &#8216;Elite Crew&#8217; and was devoted to swapping ideas on how to outwit credit-card security features, hack into other people&#8217;s computers and spread <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=3302" title="Glossary: Virus" target="_blank">viruses</a>, according to the Federal Crime Office. </p></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/11/26/four-held-in-crackdown-on-austro-german-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
