Pacnet CEO departs; acquisition rumors gain #steam http://t.co/QSCFfCcy
3 minutes ago by SuperGamePower on twitterZDNet is available in the following editions:
The Pushdo botnet is trying to evade detection by using fake SSL connections to notable Web sites such as CIA and Paypal, researcher says.
In attempt to hide the location of its command-and-control server, the Pushdo botnet has been instructing its infected zombie computers to send fake SSL (Secure Sockets Layer) connections to major Web sites, a botnet expert said on Monday.
The strange traffic targeting the Web sites--including sites for the Central Intelligence Agency (CIA), Federal Bureau of Invesigation (FBI), PayPal, Yahoo, and Twitter, according to a list at the Shadow Server Foundation--was not enough to cause any outages or slowdowns, said Joe Stewart, director of malware research at SecureWorks.
Site owners "would just see weird connections that don't seem to make sense," he said. "They look like they're trying to start an SSL handshake, but it comes in malformed and doesn't ever send anything after that first handshake attempt."
SSL is a protocol used to encrypt communications between computers for things like e-commerce and online banking.
Basically, Pushdo is using a fake SSL header in the communications sent from the infected zombies to its own command and control server, according to Stewart. "It's trying to hide itself a bit better...to make it appear on a casual inspection that it might be SSL traffic," he said.
In addition, sending a flurry of connections to legitimate Web sites could be designed to make sure the command and control server doesn't stand out, he said.
Pushdo downloads different Trojans onto infected machines and has been used to send spam as part of the Cutwail spambot, according to Stewart. It is comprised of about 300,000 infected PCs and the operators, believed to be located in Eastern Europe, are leasing out its usage to criminals, he said.
"It's a typical pay-per-install system," used to distribute banking Trojans, password stealers, ad clickers, and search hijackers, Stewart said.
This article was first published as a blog post on CNET News.
Pacnet CEO departs; acquisition rumors gain #steam http://t.co/QSCFfCcy
3 minutes ago by SuperGamePower on twitter5 SaaS adoption speed bumps to avoid http://t.co/AJQYAkOh via @zdnetasia
3 minutes ago by pmarini on twitterRT @SecMash: #InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity
3 minutes ago by suhnylla on twitterExperience trumps content in apps monetization http://t.co/MVPlf9gR
3 minutes ago by saffronistah on twitterBetter biz models needed for sustainability. http://t.co/tXuq7174
3 minutes ago by zdnetasia on twitterSudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG
18 minutes ago by NGTsummit_ASIA on twitter@ChemarieMonica : Malaysia organizations don't realize severity of cyberattacks - ZDN... http://t.co/iO8wdbz8 http://t.co/1QrdIsaV #tech
18 minutes ago by mcjimmm on twitterMalaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP
33 minutes ago by zdnetasia on twitterRT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr
33 minutes ago by nickstersss on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news
33 minutes ago by Nathiet on twitter#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity
48 minutes ago by SecMash on twitterhttp://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security
48 minutes ago by CYSEC_COM on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN
48 minutes ago by Cloud_Fail on twitterPacnet CEO departs; acquisition rumors gain steam. http://t.co/Nu2Mdcj0
48 minutes ago by zdnetasia on twitterMalaysia organizations don't realize severity of cyberattacks http://t.co/zeaxHbYa http://t.co/erFSwAUB #arcavir
48 minutes ago by V_RaV on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoidI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
4 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
5 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.