Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity
    • Networking

    Microsoft Gets Court Order to Shut Down Kelihos Botnet, Names Defendants

    By
    Fahmida Y. Rashid
    -
    September 28, 2011
    Share
    Facebook
    Twitter
    Linkedin

      Days after wrapping up its civil case against the Rustock botnet, Microsoft is back in court, this time to shut down the Kelihos network.

      Using the same technique that had worked so well in its previous campaigns against the Rustock and Waledac, Microsoft asked the United States District Court for the Eastern District of Virginia to order VeriSign to shut down 21 Internet domains associated with the Kelihos botnet, the company wrote on The Official Microsoft Blog. The botnet’s command and control servers were running on two IP addresses and 21 domains, according to Richard Boscovich, a senior attorney with Microsoft’s digital crimes unit.

      Kelihos is considered to be a small botnet, estimated to have about 41,000 infected computers under its control, according to Microsoft. Despite its size, Kelihos was responsible for nearly 4 billion spam messages per day, including stock scams, adult content, illegal pharmaceuticals and malware. Many security researchers have speculated that it was built by the same criminals that ran Waledac before Microsoft derailed that operation in March.

      Once Microsoft learned that Kelihos “shared” large portions of its code with Waledac and was somehow linked with the earlier botnet, the company “immediately began developing a plan to take out Kelihos using similar technical measures,” Boscovich wrote. “We took this action before the botnet had an opportunity to grow further,” he added.

      Microsoft does “not expect” the disruption of Kelihos to have “the breadth of impact” on the Internet that previous takedowns did, Boscovich said.

      While Microsoft got the court order for Operation b79 on Sept. 22, that allowed it to “sever the known connections” between the command and control servers and infected zombie computers, the order remained sealed until Sept. 26 when Microsoft’s lawyers issued court summons to Dominique Piatti, owner of the DotFree Group in the Czech Republic. Piatti and 22 other “John Does” have been named as defendants in the case. The sites were all taken down by early morning Sept. 27.

      This is the first time Microsoft has named defendants in its takedown attempts. “Naming these defendants also helps expose how cyber-crime is enabled when domain providers and other cyber-infrastructure providers fail to know their customers,” Boscovich wrote.

      The temporary restraining order allowed Microsoft to disable IP addresses and domains without notifying the alleged operators in advance. Microsoft has also updated the Malicious Software Removal Tool with the signature to remove the botnet agent from infected machines. The company will work with Internet service providers and Community Emergency Response Teams (CERT) to help with remediation.

      All but one of the Internet domains that VeriSign had to take offline were anonymously registered in the Bahamas, but one cz.cc domain was registered to Piatti in the Czech Republic, according to Microsoft. Criminals were directly using the domains or registering sub-domains to run command and control servers and other malicious activity, such as hosting the Mac Defender fake antivirus that targeted Mac OS X users in May.

      While Microsoft attorneys served Piatti with a court summons, they are also working with the DotFree Group to identify which domains are legitimate and get real customers back online.

      “Without a domain infrastructure like the one allegedly hosted by Mr. Piatti and his company, botnet operators and other purveyors of scams and malware would find it much harder to operate anonymously and out of sight. By taking down the botnet infrastructure, we hope that this will help deter and raise the cost of committing cyber-crime,” Boscovich wrote

      Microsoft wrapped up its civil case against the Rustock botnet and handed over the information it had collected to the Federal Bureau of Investigation on Sept. 22. While its $250,000 bounty is still in place for new information about the Rustock gang, Microsoft is redirecting all tips to the FBI’s Rustock tips email account: MS_Referrals@ic.fbi.gov.

      U.S. District Court Judge James L Robart also gave Microsoft the right to lock up 50,000 domain names and IP addresses that had been used by Rustock to infect other machines. The addresses would be removed from circulation for the next two years, Robart ruled.

      Fahmida Y. Rashid
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×