2010-03-01
Abstract
Software giant wins court order to take down botnet command and control centres.
Copyright © 2010 Virus Bulletin
A court order was obtained by Microsoft last month to force the takedown of close to 300 Internet domains associated with the Waledac botnet. The court order, obtained by Microsoft as part of its ‘Operation b49’, forces VeriSign to cut off 277 domains involved in the command and control of Waledac’s network of compromised machines.
Waledac is believed to have infected hundreds of thousands of machines around the world and has been a major source of spam – Microsoft found that, in an 18-day period in December 2009, approximately 651 million spam emails attributable to Waledac were directed to Hotmail accounts alone.
Further countermeasures have been taken by Microsoft to downgrade the remaining peer-to-peer command and control communication within the botnet, and the company reports that it has effectively shut down connections to the vast majority of Waledac-infected computers.
Microsoft hints that more such legal and industry operations are in the pipeline.