
Employees of the Microsoft Digital Crimes Unit information security department disabled the growing botnet, consisting of computers infected with Nitol virus, reports CNews.ru with reference to the Microsoft blog.
Microsoft says that over the past six months they have taken part in the disconnection of the second botnet. At the end of spring, the specialists of the software corporation, together with colleagues from other companies, held a successful raid against a zombie network created by the Zeus malicious programs.
The new operation to turn off Botnet received the code name Operation B70 and began in August 2011 in China. Then Microsoft experts, having visited several Chinese cities, purchased twenty new personal computers, including about ten laptops, with the Windows XP SP1 and SP3 operating system.
Having checked everyone, on three of them researchers found various malware. Of the three programs of researchers, Nitol, designed to conduct DDOS attacks and has the ability to independently copy on all external media connected to the computer. According to official information, the virus belongs to the category of malicious software called backdores.
In the process of investigation, Microsoft found out that in most cases Nitol addresses the 3322.org domain in order to get the address of the command server. Turning to the American company Nominum, experts were able to filter traffic, blocking all the requests of malware to the specified domain.
Then Microsoft received permission from the District Court in the state of Virginia to deactivate this domain starting on September 17.
Peng Yun, the owner of the Bei TE KANG MU Software Technology, behind which is the criminal domain, said that he was not aware that domain 3322.org would be closed. He emphasized that he was not going to put up with the fact that Microsoft captured his domain. Yun added that 2.85 million domains were registered for his company and he cannot track down which of them are used to spread viruses.
Recall that Backdor is a program that allows an attacker to install a cracker on the victim’s computer in order to subsequent access to a full rights system. In addition, he provides an attacker with the opportunity to remotely include a webcam and a microphone on the victim’s computer and fix the pressing of each key (Keiloger function).
Botnet is called a network consisting of hosts with "bots" launched on them (reduction from the word "robot") - autonomous software. Most often, the bot in the batch network is a program secretly installed on the victim’s computer and allows the attacker to perform certain actions using the resources of the infected computer.
Botnets are used for various kinds of illegal or undesirable activities: spam mailing, passwords for passwords on a remote system, attacks on refusal to maintain (DDOS), etc. Botnets attacks are able to disable not only large Internet resources, but also entire network segments.