Jul22
7:51 am (UTC-7)   |   by Jonell Baltazar (Advanced Threats Researcher)

Early this week, the KOOBFACE Command and Control (C&C) servers issued a new command to its downloader component. This new command identifies a list of IP addresses to be used by the downloader component as Web or relay proxies to retrieve subsequent commands and components.

In the old KOOBFACE architecture (see Figure 1), the downloader directly connects to an available C&C to receive commands. However, the new command seen early this week actually changes the KOOBFACE botnet architecture to something more like the diagram in Figure 2.

Click for larger view Click for larger view

This new command acts as a redundancy layer to the old architecture and probably as a response to KOOBFACE domain takedowns. The upgraded KOOBFACE architecture makes it possible for the KOOBFACE botnet to survive even if all of its C&C domains are shut down given that the list of IP addresses (KOOBFACE zombies) can also host updated KOOBFACE commands and components.

KOOBFACE made waves in social networking sites by using infected users’ profiles to infect other users and therefore propagate. We have chronicled its activities in the following blog posts:

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!




12 Responses to “New KOOBFACE Upgrade Makes It Takedown-Proof”

Trackbacks

  1. securitybananas.com » New KOOBFACE Upgrade Makes It Takedown-Proof
  2. TrendMicro (TrendMicro)
  3. rik_ferguson (Rik Ferguson)
  4. arbornetworks (arbornetworks)
  5. adamclatworthy (Adam Clatworthy)
  6. tonys3kur3 (Tony Bradley)
  7. Kendall_Thomas (Kendall_Thomas)
  8. HappyComputerTX (Happy Computer)
  9. New KOOBFACE Upgrade Makes It Takedown-Proof | Trend Micro | Malware Blog « Jared Rimer’s Technology blog and podcast
  10. jrimer2008 (Jared Rimer)
  11. Kevin Decherf’s blog » Koobface se met à la tolérance de panne
  12. Tech Thoughts Daily Net News – July 24, 2009 « Bill Mullins’ Weblog – Tech Thoughts

Leave a Reply



© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice