查看: 2153|回复: 13
收起左侧

[一般话题] MMPC病毒播报:继续清理脱机 Rustock 网络(微软大战僵尸网络)

[复制链接]
飞霜流华
发表于 2011-7-6 13:38:25 | 显示全部楼层 |阅读模式
原文:Rustock network offline, cleanup continuesmsft-mmpc
5 Jul 2011 7:54 AM

  • Comments0


In an effort to continue raising awareness about the Rustock botnet that was successfully taken down on March 16th, the Microsoft Digital Crimes Unit (DCU), the Microsoft Malware Protection Center (MMPC) and Trustworthy Computing released a new Special Edition Security Intelligence Report (SIR) today titled "Battling the Rustock Threat". Our telemetry indicates that the bot network is now less than half the size it was prior to being taken offline. However, although our global detection results show a sharp decline in Rustock-related activity, we are still working with our partners to clean the remaining, infected machines of this threat. There are still infected machines out there, orphaned from the now-offline Win32/Rustock command and control infrastructure - and the malware authors are still at large. However, through our partnerships with CERTs and ISPs worldwide, we're making strides to identify and remove the Rustock threat from these orphaned systems and have had considerable success in the early parts of this work.
This report gives an overview of the Win32/Rustock family of rootkit-enabled backdoor trojans, its functionality and how it works. It also shows the direct impact of the takedown operation. The SIR also verifies something we have long believed: that Rustock-infected computers are also very likely to be infected with other malware. For example, DCU and MMPC conducted an experiment in which they infected a computer with Win32/Harnig, which is known to infect a computer with Rustock, in order to see what additional malware was installed. Within five minutes of installation, a wide variety of additional malware and potentially unwanted software had been downloaded and installed onto the infected computer – and many of these threats are themselves designed to eventually download even more malware. The SIR also has details about how we defeated Rustock in the courts, providing lots of previously undisclosed details from the legal and enforcement sides of the operation.

翻译:
继续清理脱机 Rustock 网络
为了继续提高对3 月 16 日成功拿下的Rustock僵尸网络的认识,微软数字犯罪单位(DCU)、Microsoft 恶意软件保护中心(MMPC) 和可信赖计算机机构今天新公布了 标题为"作战 Rustock 威胁"的Rustock 僵尸网络特别版安全情报报告 (SIR)。我们的遥测指示僵尸网络现在是它在已经脱机之前的一半大小。不过,虽然我们全球的检测结果显示与 Rustock相关的活动在急剧下降,但是我们仍然正与我们的合作伙伴清除剩余的受这种威胁感染的机器。现在仍有受感染的机器,从现在脱机的Win32/Rustock命令中孤立出来并控制基础设施,而且恶意软件作者仍然在逃。但是,我们通过证书及与世界各地的供货商合作,我们正在努力确定和从这些孤立的系统中删除 Rustock 威胁,并在这项工作的最初阶段取得了相当大的成功。

本报告概述了Win32/Rustock家族的 rootkit 启用后门特洛伊木马程序的功能以及它如何工作。它还显示了直接关闭操作的影响。ISR还验证了我们一直相信的东西:被 Rustock 感染的计算机也是很有可能被其他恶意软件感染。例如,DCU 和 MMPC 进行实验,他们用Win32/Harnig(这是已知能与 Rustock一起感染感染计算机恶意软件)来感染电脑,以查看哪些其他恶意软件一并安装在了这台电脑。在安装后五分钟内,各种其他恶意软件和潜在有害的软件已经下载并安装到感染病毒的计算机中 ,并且许多这种威胁都是自己设计的来最终下载更多的恶意软件。ISR也从运作的法律和执法方面的详细信息方面提供许多以前没有透露具体的有关我们如何打败 Rustock细节。

评分

参与人数 1人气 +1 收起 理由
一晴空 + 1 辛苦了:)

查看全部评分

Mr.XCLK
发表于 2011-7-6 13:48:36 | 显示全部楼层
很好,继续支持MMPC
驭龙
发表于 2011-7-6 13:52:22 | 显示全部楼层
唉!你把这个下载了吧,之后复制到帖子里,何必翻译的那么累,还不完整

http://www.microsoft.com/downloa ... p;displaylang=zh-cn
飞霜流华
 楼主| 发表于 2011-7-6 13:58:48 | 显示全部楼层
zdshsls 发表于 2011-7-6 13:52
唉!你把这个下载了吧,之后复制到帖子里,何必翻译的那么累,还不完整

http://www.microsoft.co ...

你这个是完整报告了,我的则是MMPC的博客上弄下来的,而且这个文件pdf的,一弄文档编辑,复制下来就是乱码
ps:其实这些东西我也不怎么想弄,但是人气实在太低了,看着心酸呐,沾点边的我就拿过来凑个数吧
驭龙
发表于 2011-7-6 14:35:35 | 显示全部楼层
本帖最后由 zdshsls 于 2011-7-6 14:36 编辑
wy1091727248 发表于 2011-7-6 13:58
你这个是完整报告了,我的则是MMPC的博客上弄下来的,而且这个文件pdf的,一弄文档编辑,复制下来就是乱码 ...


我再帮你凑个数吧,呵呵。

怪不得我最近回来发现咱们MSE区怎么变成病毒播报区了呢。呵呵

人气不好不要气馁,慢慢来吧。如果我这边一切顺利,我一周之内就有可能回来,但是如果不顺利的话,我可能就要无限期推迟回归时间。

人气不是版区最重要的(当然人气也是版区必不可少的,我只是想说,你别太在意这个),不要太在意,主要还是要保证质量。
一晴空
发表于 2011-7-6 14:47:59 | 显示全部楼层
狮子今天速度真快啊支持了啊
XMonster
发表于 2011-7-6 16:57:32 | 显示全部楼层
一晴空 发表于 2011-7-6 14:47
狮子今天速度真快啊支持了啊

插一句:看到我给你的PM了麽?  
一晴空
发表于 2011-7-6 17:13:50 | 显示全部楼层
dm34343667 发表于 2011-7-6 16:57
插一句:看到我给你的PM了麽?

那啥?什么信息,没收到,抱歉啊,能在PM一遍吗?
ostar843
发表于 2011-7-6 17:45:53 | 显示全部楼层
偶也来添点人气@@@
钢铁侠
发表于 2011-7-6 19:21:49 | 显示全部楼层
添点人气,希望MSE更加重视中国区样本收集。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 11:11 , Processed in 0.119999 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表