Home→Blog→Virus Watch→August 29 2007→Botnet losing ground
|
20 May Jumcar. From Peru with a focus on Latin America [First part] Jorge Mieres 18 May NoSuchCon 2013 Stefano Ortolani 17 May Malicious PACs and Bitcoins Fabio Assolini 14 May Microsoft Updates May 2013 - Slew of Internet Explorer Critical Vulnerabilities, Kernel EoP, and Others Kurt Baumgartner 13 May Telecom fraud — phishing and Trojans combined Dong Yan 27 Apr CeCOS VII Michael Join our blog You can contribute to our blog if you have +100 points. Comment on articles and blogposts, and other users will rate your comments. You receive points for positive ratings. |
Over the last couple of weeks we've been closely following the behaviour of a botnet with a C&C (command and control) center based on a popular web-based engine.
We waited for it to grow (see previous posts) and it was interesting to see the increase in the number of infected machines. And now the scale of the botnet is shrinking.
Today the botnet was made up of 6000 zombies, even though a week and a half ago there were more than 14 000! What happened? We took a look and found that there's a significant difference between the total number of infections and actual number of infected machines.
Let's take a look at the zombie network stats that we got today:

Subtract "GENERAL NUMBER BOTS" from "GENERAL NUMBER OF INFECTIONS" and there's a difference of about 10 000. This means the botnet is losing its bots!
Now let's compare the very same stats with the ones that we captured while the botnet was still growing:

The difference between "GENERAL NUMBER OF INFECTIONS" and "GENERAL NUMBER BOTS" is less than 500!
These differences are explained by the fact that AV companies have been busy detecting malicious files which were used to create the botnet. The time taken before all AV vendors detected the files was several days. During this time bots were detected and removed from PCs and this is why the botnet is losing its clients. And every day, as more and more users update their AV databases the botnet continues to lose ground...
1 comments
|
2011 Nov 04, 16:55
How can denounce a Botnet Id like know how can be denounce a botnet. How can be input a IP address of a botnet that attack my mail server, for example. |
Analysis
Blog