BleepingComputer.com: DNSChanger Botnet taken down

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

DNSChanger Botnet taken down FBI asks victims to contact them

#1 User is offline   Andrew 

  • Bleepin' Night Watchman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 7,425
  • Joined: 05-December 05
  • Gender:Not Telling
  • Location:Right behind you

Posted 10 November 2011 - 05:26 PM

The US Federal Bureau of Investigation, in cooperation with Dutch police and several companies and universities, has effected the take-down of the DNSChanger botnet. The take-down involved the seizure of servers and the indictment of several Estonians affiliated with the shady hosting company Rove Digital. An unnamed Russian suspect remains at large.

Quote

Beginning in 2007, the cyber ring used a class of malware called DNSChanger to infect approximately 4 million computers in more than 100 countries. There were about 500,000 infections in the U.S., including computers belonging to individuals, businesses, and government agencies such as NASA. The thieves were able to manipulate Internet advertising to generate at least $14 million in illicit fees. In some cases, the malware had the additional effect of preventing users’ anti-virus software and operating systems from updating, thereby exposing infected machines to even more malicious software.
-FBI Press Release

The FBI has posted an online tool which can tell you if your computer's DNS settings have been tampered with, which can be found here. The FBI would also like anyone affected by this malware to contact them using this form.

The DNS Changer Working Group, which was formed to aide in the take-down and clean up, expects to install their own DNS servers in place of the malicious ones. These servers will allow the DCWG to alert users of infected computers that their system was compromised.

Further Reading:
http://www.theregister.co.uk/2011/11/10/botnet_take_down_clean_up/
http://countermeasures.trendmicro.eu/how-to-check-if-you-are-a-victim-of-operation-ghost-click/
http://blog.trendmicro.com/esthost-taken-down-%E2%80%93-biggest-cybercriminal-takedown-in-history/

Resources:
FBI's DNSChanger Detection Page
FBI's DNSChanger Victim Contact Form


The malicious DNS servers fall into these IP address ranges:
85.255.112.0 - 255
67.210.0.0 - 255
93.188.160.0 - 255
77.67.83.0 - 255
213.109.64.0 - 255
64.28.176.0 - 255

This post has been edited by Andrew: 10 November 2011 - 05:51 PM

Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Posted Image
Boredom Software Stop Highlighting Things

#2 User is offline   keyboardNinja 

  • Bleepin' Ninja
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,791
  • Joined: 19-December 09
  • Gender:Male
  • Location:teh interwebz

Posted 10 November 2011 - 07:40 PM

:clapping:
PICNIC - Problem In Chair, Not In Computer

Posted Image Posted Image

20 Things I Learned About Browsers and the Web

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users