Microsoft halts another botnet: Kelihos

Microsoft has put a halt to the Kelihos botnet and is accusing a Czech resident of hosting the botnet and using it to deliver spam and steal data, the company has said.

Kelihos, also known as "Waledac 2.0" after a previous botnet that Microsoft shut down last year, comprised about 41,000 infected computers worldwide and was capable of sending 3.8 billion spam emails per day, according to Microsoft.

The complaint filed last week in the US District Court for the Eastern District of Virginia accuses Dominique Alexander Piatti, Dotfree Group SRO and John Does 1-22 of infecting victim computers with malware to create the Kelihos botnet, using it to send unregulated pharmaceutical and other spam, harvest emails and passwords, conduct fraudulent stock scams and, in some cases, promote sites dealing with sexual exploitation of children.

Meanwhile, sub-domains were allegedly used to infect Mac computers with MacDefender scareware, according to the complaint. Piatti could not immediately be reached for comment.

In addition to filing complaints, Microsoft also is using a relatively new tactic of filing restraining orders to get court permission to sever the connections between the botnets and the individual infected computers, known as "zombies". This stops the botnet from continuing to operate and grow.

Microsoft also plans to work with internet service providers and Community Emergency Response Teams (CERTs) to help clean up computers that were infected and used in the botnet. As part of that process, the Microsoft Malware Protection Center will add the Win/32 Kelihos family in a second release of the Malicious Software Removal Tool later today.

"Without a domain infrastructure like the one allegedly hosted by Mr Piatti and his company, botnet operators and other purveyors of scams and malware would find it much harder to operate anonymously and out of sight. By taking down the botnet infrastructure, we hope that this will help deter and raise the cost of committing cybercrime," Richard Domingues Boscovich, senior attorney with the Microsoft Digital Crimes Unit, wrote in a blog post.

The case also highlights an industry-wide problem related to the stealth use of sub-domains, he said. "Under US law, even pawn brokers are more effectively regulated to prevent the resale of stolen property than domain owners are to prevent the use of their digital properties for cybercrime. For example, pawn shop operators must require a name, address and proper identification from customers, while by contrast there are currently no requirements necessitating domain hosts to know anything about the people using their sub-domains — making it easy for domain owners to look the other way."

This is the third botnet — following Waledac, and Rustock earlier this year — that Microsoft has taken down using these same legal and technical measures, but it's the first time a defendant has been named in one of the company's civil cases involving a botnet.

Via CNET

Talkback

Microsoft also plans to work with internet service providers and Community Emergency Response Teams (CERTs) to help clean up computers that were infected and used in the botnet. As part of that process, the Microsoft Malware Protection Center will add the Win/32 Kelihos family in a second release of the Malicious Software Removal Tool later today

myronmyron January 25th, 2012
Report offensive content Reply (0) (0)

Yeah i accept with myron!!

SabrinaSSabrinaS February 7th, 2012
Report offensive content Reply (0) (0)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

The rural Silicon Valley http://t.co/jhEFQwSX

JobWatch: where the ICT jobs are http://t.co/e6gQvhxz via @zdnetaustralia #ICT #recruitment

The rural Silicon Valley: What happened in Senate Estimates this week? What's the issue with tech company taxes?... http://t.co/Umoa7CHX

Sweet: "Customers are picking the top fibre plan that is available on the #NBN more than any other plan" http://t.co/yUFHdYFc

RT @CorrieB: An iPad for every child: Inevitable or impossible? http://t.co/I7uS8l9s Thx to @timbuckteeth for this; http://t.co/jxkqIRIp

Interesting tech analysis podcast re: phone cloning and Craig Thomson from zdnet http://t.co/p8jlCvvG

@zdnetaustralia Thoughtful piece to end the week on. Thanks @joshgnosis

Triple J's Spotify conundrum http://t.co/iy1e2DRp via @zdnetaustralia

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

BYOD for iOS devices is not a big deal, provided a passcode is enforced and jailbroken devices are excluded. But if Google can sort out ...

38 minutes ago by umbria on BYOD too immature for us: Human Services

Triple J not bound to advertising rules like its broadcast. No diff to ABC online or magazines though... http://t.co/JPUr7Fv4

Triple J's Spotify conundrum: Has Triple J managed to find the balance between meeting editorial policy and keep... http://t.co/8UYsHZ6D

Thank you, Tasmania, for helping NBNCo get the design optimised. Heard a great anecdote this week. Four kids at a little school in one of...

44 minutes ago by umbria on NBN's Tassie upgrade to cost $1.3 million

RT @joshgnosis: Listening to Triple J on Spotify has ads for Commonwealth Bank. But that's okay apparently. http://t.co/O7zmcpvT

Listening to Triple J on Spotify has ads for Commonwealth Bank. But that's okay apparently. http://t.co/O7zmcpvT

How does Triple J find the balance with meeting editorial policy and keeping up with the latest technology? http://t.co/qdWgybfm ^jt

Agree AWY

Early days but the take-up rate for the fastest speed tier needs to accelerate to justify the huge Cap-ex.

53 minutes ago by Vasso Massonic on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

NBN users opt for 100Mbps http://t.co/ftKGRzye

#IT Priorities: #servers and #storage: webinar sponsored by @IBM http://t.co/BGq8LYd5 via @zdnetaustralia

Post 'social' improved speed to information and context: By Oliver Marks | May 24, 2012, 9:47pm PDT... http://t.co/VGN2hxtp #socialmedia

RT @zdnetaustralia: Should bug hunting for biometric systems be restricted to govt and industry? http://t.co/oj0oOkv7 ^ML

Exploring: http://t.co/WzikDISk

There's trouble with three major Linux desktop application developers. #Linux http://t.co/uR07K9W6

IT Priorities: servers and storage http://t.co/BGq8LYd5 via @zdnetaustralia

Couple of things: Firstly the most important one: "We expect to see that ratio shifting around a bit,"- well says it all almost. Basica...

1 hour ago by AWY on NBN users opt for 100Mbps

Exploring: NBN users opt for 100Mbps: Customers are picking the top fibre plan that is available o... http://t.co/9PwLO0NU #ICTChallenge

Exploring: NBN users opt for 100Mbps: Customers are picking the top fibre plan that is available o... http://t.co/JWTrVow1 #ICTChallenge

Exploring: http://t.co/8iFmRUbZ

NBN users opt for 100Mbps http://t.co/atP8fi1L

Can #Windows Phone bring a new challenge? http://t.co/CpTjZ2lk via @zdnetaustralia

NBN users opt for 100Mbps - ZDNet Australia http://t.co/eVVB5xyS

NBN users opt for 100Mbps - ZDNet Australia http://t.co/4oaTruaN

Where's Mathew whats-his-face complaining about how the secret nasty NBNCo plan is all about "forcing" people onto higher ARPU? Sounds l...

1 hour ago by Gwyntaglaw on NBN users opt for 100Mbps

Story filed for @zdnetaustralia. Please don't tell @engochick that I've waffled on for 1200 words. I'm exhausted now.

RT @markjohnston_au: Australian Privacy Laws catching up with the world http://t.co/OCU7uwqe but will this help change tickbox security to real protection?

Given the early priority given to Tasmania, it is around 90% likely that the entire state will receive the full NBN rollout as originally...

1 hour ago by Gwyntaglaw on NBN's Tassie upgrade to cost $1.3 million

NSW outlines datacentre migration plans - ZDNet Australia: NSW outlines datacentre migration plansZDNet Australi... http://t.co/MosIfczQ

NBN users opt for 100Mbps - ZDNet Australia: Brisbane TimesNBN users opt for 100MbpsZDNet AustraliaCustomers are... http://t.co/T5oBSVZQ

A relevant lesson for NZ - NBN users opt for 100Mbps http://t.co/KScaSdRI via @zdnetaustralia

RT @ninefold: Interesting Q&A on #cloud security, debating Patriot Act & more: ZDNet Australia http://t.co/qc933yKJ

If you’re running 1:1 then whoever it was that did the original design did not future proof. You should aim to 10:1 for small use stati...

1 hour ago by amckern on 30 servers to 7: BUPA redoes virtualisation

Yes, after all when you do your personal tax return, you don't say to your accountant: "oh, give the government a couple of thousand out...

2 hours ago by meski on Much ado about Google's tax

That would be Ayn, not Ann. And if you read Atlas Shrugged and came away with the impression of selfish, there's not much I can say to c...

2 hours ago by meski on Much ado about Google's tax

I think the CBA point here is fairly much moot now. There was some, limited, argument for it before the NBN began, but as many people hav...

3 hours ago by seven_tech on NBN cost-benefit analyses are so 2011

Reading this article is like stepping back in time. If I was Paul Berryman I would hang my head in shame. How embarrassing!!! I can’t b...

6 hours ago by MikeSkoey on 30 servers to 7: BUPA redoes virtualisation

The registration sticker provided a visual reminder to the driver to renew regardless of what happened to the renewal letter. The experie...

6 hours ago by dccharron on NSW ditches rego stickers for tech

"xfire: Why is telecommunications being treated different to roads, water and electricity?" Good question, my guess is AUS is far behind...

6 hours ago by ngoctranminh on Five pros and cons of the NBN

Thanks for the response Luke, Given that the quotes are accurate, then the person in charge of the Vic Health App needs to find another j...

6 hours ago by butterflyeffecs on Android fragmentation steers Vic Health

Nice analogy. Another factor is whether you can find 50 people with powerful enough weapons. Minassian's argument is essentially that the...

6 hours ago by Mukimu on National Botnet Network coming: Earthwave

It's nice to see Tas finally get some decent internet connectivity, for too long Tas has been stooged on decent internet connectivity but...

7 hours ago by Jingles on NBN's Tassie upgrade to cost $1.3 million

Who is Luke Hartsuyker? He must be the Apprentice FUDster. As PaulPC has already said regional consumers want, deserve and are entitled...

7 hours ago by dickster on Regional review highlights NBN, mobile

Its good to see the NBN keeping up with the latest equipement & letting the people benefit from it. After all thats why it was a trial, ...

7 hours ago by fibretech on NBN's Tassie upgrade to cost $1.3 million

Shadow Minister for Regional Communications Luke Hartsuyker has got it wrong. Regional consumers want improved mobile services AND the NB...

8 hours ago by PaulPC on Regional review highlights NBN, mobile

Just remember that Google haven't broken any laws here, they're just doing what all their other multinational competitiors do; minimise t...

9 hours ago by Pachanga on Much ado about Google's tax

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar