• Trend Micro
  • About TrendLabs Security Intelligence Blog
Search:
  • Home
  • Categories
    • Ransomware
    • Vulnerabilities
    • Exploits
    • Targeted Attacks
    • Deep Web
    • Mobile
    • Internet of Things
    • Malware
    • Bad Sites
    • Spam
    • Botnets
    • Social
    • Open source
Home   »   Bad Sites   »   One Month to DNS Changer Server Shutdown

One Month to DNS Changer Server Shutdown

  • Posted on:June 8, 2012 at 2:47 pm
  • Posted in:Bad Sites
  • Author:
    Jonathan Leopando (Technical Communications)
0

The extension granted in March for the DNS servers run by the Internet Systems Consortium (ISC) for victims of the DNS Changer malware expires in a month. To recap: after the FBI (working with a cadre of private industry partners, including Trend Micro researchers) disconnected the ESThost/Rove Digital “rogue” DNS infrastructure in New York and Chicago as part of operation “ghostclick”, ISC acted under a custodial court order to install & maintain legitimate DNS servers for affected users.

The DNS Changer Working Group (DCWG) estimates that more than 350,000 users are still affected by DNS changer malware. Unlike the previous shutdown date in March – which was put off by a federal court – there will be no extension this time. In addition to checkup sites like the one maintained by the DCWG, commonly used sites like Facebook and Google have begun notifying their users as well. We urge users to check if they are affected by this problem; if they are they can go to the links provided by the DCWG or contact their ISP for help removing this threat. Users who ignore these warnings face being cut off from the entire Internet once the court order expires on July 9.

Trend Micro product users are protected from DNS Changer malware, detected as DNSCHANG. DNSCHANG is actively detected and removed from your system.

For details of the Esthost/Rove Digital takedown, you can consult the following blog posts:

  • Esthost Taken Down – Biggest Cybercriminal Takedown in History
  • 2011 in Review: Security Wins

The Esthost/Rove Digital takedown is still, to this day, the biggest takedown in terms of the size of the botnet taken offline. The following infographic compares it to previous takedowns:

Learn how to protect Enterprises, Small Businesses, and Home Users from ransomware:
ENTERPRISE »
SMALL BUSINESS»
HOME»
Tags: DNSDNS Changerdnschangerjuly 9

Featured Stories

  • systemd Vulnerability Leads to Denial of Service on Linux
  • qkG Filecoder: Self-Replicating, Document-Encrypting Ransomware
  • Mitigating CVE-2017-5689, an Intel Management Engine Vulnerability
  • A Closer Look at North Korea’s Internet
  • From Cybercrime to Cyberpropaganda

Security Predictions for 2019

  • Our security predictions for 2019 are based on our experts’ analysis of the progress of current and emerging technologies, user behavior, and market trends, and their impact on the threat landscape. We have categorized them according to the main areas that are likely to be affected, given the sprawling nature of the technological and sociopolitical changes under consideration.
    Read our security predictions for 2019.

Business Process Compromise

  • Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

Recent Posts

  • February Patch Tuesday: Batch Includes 77 Updates That Cover Flaws in Internet Explorer, Exchange Server, and DHCP Server
  • Trickbot Adds Remote Application Credential-Grabbing Capabilities to Its Repertoire
  • Windows App Runs on Mac, Downloads Info Stealer and Adware
  • Linux Coin Miner Copied Scripts From KORKERDS, Removes All Other Malware and Miners
  • Various Google Play ‘Beauty Camera’ Apps Send Users Pornographic Content, Redirect Them to Phishing Websites and Collect Their Pictures

Popular Posts

  • Going In-depth with Emotet: Multilayer Operating Mechanisms
  • February Patch Tuesday: Batch Includes 77 Updates That Cover Flaws in Internet Explorer, Exchange Server, and DHCP Server
  • Various Google Play ‘Beauty Camera’ Apps Send Users Pornographic Content, Redirect Them to Phishing Websites and Collect Their Pictures
  • Linux Coin Miner Copied Scripts From KORKERDS, Removes All Other Malware and Miners
  • Trickbot Adds Remote Application Credential-Grabbing Capabilities to Its Repertoire

Stay Updated

  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, 日本, 대한민국, 台灣
  • Latin America Region (LAR): Brasil, México
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Österreich / Schweiz, Italia, Россия, España, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © Trend Micro Incorporated. All rights reserved.