Categorized | Security

Massive Drop in Number of Active Zeus C&C Servers

I always check the ZeuS Tracker statistics to get some information about the trend of the active ZeuS Command&Control servers. This morning I was really surprised what I saw on the ZeuS Tracker statistic page:


Massive drop of active ZeuS C&C servers on 2010-03-09

As you can see in the chart above, on March 9th 2010, the number of active ZeuS C&C servers dropped from 249 to 181! The first thing I thought was: There has to be some problem with the ZeuS Tracker cron script. I checked the script – everything looked ok. So the massive drop of ZeuS C&C server is fact. I noticed that six of the worst ZeuS hosting ISP suddently dissapeared from the ZeuS Tracker.

I verified the subnets of the affected ISP and came to the conclusion that Troyak-as (AS50215), the upstream provider for the six worst ZeuS hosting ISPs, was cut from the internet on 2010-03-09. As a result, the following ISPs lost their internet connetivity which finally resulted in a massiv drop in the number of active ZeuS C&C servers:

AS number: AS50390
AS name: SMILA-AS Pavlenko Tetyana Oleksandrivna
Subnet: 193.105.0.0/24
Status: Withdrawn
# of ZeuS C&Cs: 17
Spamhaus SBL: Not listed

AS number AS42229
AS name: MARIAM-AS PP Mariam
Subnet: 91.201.196.0/22
Status: Withdrawn
# of ZeuS C&Cs: 18
Spamhaus SBL: #SBL86729

AS number: AS49934
AS name: VVPN-AS PE Voronov Evgen Sergiyovich
Subnet: 193.104.41.0/24
Status: Withdrawn
# of ZeuS C&Cs: 8
Spamhaus SBL: #SBL82374

AS number: AS44107
AS name: PROMBUDDETAL-AS Prombuddetal LLCst
Subnet: 91.201.28.0/22
Status: Withdrawn
# of ZeuS C&Cs: 5
Spamhaus SBL: #SBL82408

AS number: AS50033
AS name: GROUP3-AS GROUP 3 LLC.
Subnet: 193.104.94.0/24
Status: Withdrawn
# of ZeuS C&Cs: 8
Spamhaus SBL: #SBL85667

AS number: AS12604
AS name: CITYGAME-AS Kamushnoy Vladimir Vasulyovich
Subnet: 193.104.27.0/24
Status: Withdrawn
# of ZeuS C&Cs: 12
Spamhaus SBL: #SBL81900

In total, 68 went down – It was the biggest drop in number of ZeuS C&C servers I’ve ever seen! Some guys have done a great job :D

*** UPDATE 21:03 (UTC) ***
Bad news – it seem that TROYAK-AS has found a new upstream provider to serve their malware to the world:

AS50215 TROYAK-AS Starchenko Roman Fedorovich

Upstream Adjacent AS list
AS44051 YA-AS Professional Communication Systems

Source: http://cidr-report.org/cgi-bin/as-report?as=AS50215

As you can see on Robtex, YA-AS has just one upstream provider called NASSIST-AS (AS29632). Let’s hope that this is just the last breath of TROYAK-AS and that NASSIST-AS will cut their peerings with YA-AS quickly.

*** STATUS 2010-03-11 07:15 (UTC) ***
I just took another look into the ZeuS Tracker statistics – the number of active ZeuS C&Cs is still falling! In total, I’ve counted 104 ZeuS C&C servers which are no longer reachable from the internet!


ZeuS Tracker statistics as of 2010-03-11

As mentioned on the last update from 21:03 UTC, Troyak just found a new upstream provider. This means: Troyak-AS is reconnected to the internet since yesterday. Anyway, I just checked the those ZeuS C&C servers which where routed by Troyak – all of them are still offline.

*** UPDATE 2010-03-11 11:50 (UTC) ***
It’s a very busy day – Troyak is trying hard to get back online. This morning they disappeared again from the global BGP routing table and are now being routed by RTCOMM-AS (AS8342 RTComm.RU), located in Russia:

AS50215 TROYAK-AS Starchenko Roman Fedorovich

Upstream Adjacent AS list
AS8342 RTCOMM-AS RTComm.RU Autonomous System

*** UPDATE 2010-03-11 21:30 (UTC)
Bad news: Since Troyak started their peering with RTCOM-AS, the number of active ZeuS C&C servers has increasted from 149 up to 191. For now, more than 40 ZeuS C&C servers are back online! This means that the cybercriminals are now able to move the stolen data to a safe place or a backup server. Additionally, the cybercriminals are able to update their config files served to the infected clients to set up a fallback server (if Troyak will disappear from the internet again).

*** UPDATE 2010-03-12 11:10 (UTC) ***
Another update: Troyak has changed their upstream provider again and is now being routed by NLINE-AS (AS25189 – JSC Nline):

AS50215 TROYAK-AS Starchenko Roman Fedorovich

Upstream Adjacent AS list
AS25189 NLINE-AS JSC Nline

Further links

  • ZeuS Tracker
  • Robtex: Troyak-as Starchenko Roman Fedorovich
  • Krebs on Security: Dozens of ZeuS Botnets Knocked Offline
  • The Register: One-third of orphaned Zeus botnets find way home
Bookmark, tagg it or email it to a friend:
[Bloglines] [del.icio.us] [Digg] [Facebook] [Google] [Mister Wong] [MySpace] [Slashdot] [Technorati] More »



View full post on abuse.ch

Related Posts
  • Blog: Active Koobface C&C servers hit a record high – 200+ and counting
    As I was saying in the yesterday's blog post, we were expecting the number of Koobface C&C servers to start growing sometime this week View full post on Securelist / All Updates...
  • AS50215 Troyak-as Taken Offline, Zeus C&Cs Drop from 249 to 181
    2nd update for Friday, March, 12, 2010 - Troyak-AS is down again - "This AS is not currently used to announce prefixes in the global routing table, nor is it used as a visible transit AS." UPDATED: ...
  • PSN update now live across the U.S., go change your password now
    In case you missed it — and you very well might have considering what time this ball got rolling — Sony has officially flipped the switch on the PlayStation Network, restoring service in a limited...
  • Rogue number crunching
    Researcher Patrick Jordan put together some statistics on the various Rogues he sees on a daily basis, and I thought it made for some interesting reading. How are the rogue AV products shaping up in...
  • 2 DNS Name Servers of DNS.BE experienced unusual high workload
    DNS.BE, the Belgian organization that manages all registrations of domainnames under the .be TLD,  reported that the DNS name servers did get an unusual high workload, up to 6 times more queries than ...
  • More on the “massive” SQL injection attack
    Alas, the news was published on April 1st. But it is not a joke. Curious, I spent a bit of time today researching it (when I really was supposed to be doing other things), and while the “lizamoon” ...
  • Trend Micro Sinkholes and Eliminates a ZeuS Botnet C&C
    In February 2011, we successfully collaborated with CDMON, a registrar, to gain control of a ZeuS botnet command-and-control (C&C) server, thereby rendering it ineffective. Our success gave us the...
  • ZeuS Source Code Already in the Wild
    For about two weeks now, the ZeuS source code has been making its way around to different people. Many people have been offering it up for sale on multiple forums, but lots of times it is only pieces ...
  • ZeuS 2.0.8.9 and the Ghost Panel
    Before ZeuS author Monstr/Slavik handed over his source code to SpyEye author Harderman/Gribodemon, the last known ZeuS version was 2.0.8.9. The ZeuS crimeware, which exponentially grew in popularity ...
  • Carberp hits ZeuS and AV software
    We have talked in the last blog post about how SpyEye trojan evolved during the time, illustrating some of its technical features and the encryption algorithm used by the trojan to decrypt the config...

10 Responses to “Massive Drop in Number of Active Zeus C&C Servers”

  1. AS50215 Troyak-as Taken Offline, Zeus C&Cs Drop from 249 to 181 « Random Chaos says:

    [...] AS50215 Troyak-as, the cybercrime-friendly virtual neighborhood that was a key component in the hosting infrastructure for all of the Zeus-crimeware serving campaigns during Q1 of 2010, has been taken offline, resulting in a pretty evident drop in Zeus C&Cs, according to this graph courtesy of the ZeusTracker. [...]

  2. Desactivan gigantesca red de PC zombies, pero la reconectan | Shadow Security says:

    [...] Systems informó que hasta el 25% de las computadoras infectadas por ZeuS en el mundo fueron desconectadas durante la noche de la colosal red [...]

  3. » El botnet Zeus pierde un buen número de servidores NoticiasTech says:

    [...] [vía abuse.ch] [...]

  4. After Takedown, Botnet-linked ISP Troyak Resurfaces (PC World) | Techn0logy says:

    [...] is a botnet kit used by a large number of cybercriminals. Researchers have counted 249 Zeus command-and-control servers to date. Another Internet service provider named Group 3 was also knocked offline Wednesday. It has not [...]

  5. Open Systems Journal » Blog Archive » etc: Another botnet takes a beating as Kazakh ISP Troyak is taken offline, temporarily disabling most of the command-and-control servers for the Zeus network. says:

    [...] Read More: Computerworld, abuse.ch [...]

  6. Another botnet takes a beating as Kazakh ISP Troyak is taken offline, temporarily disabling most of the command-and-control servers for the Zeus network. says:

    [...] disabling most of the command-and-control servers for the Zeus network. Read more: Computerworld , abuse.ch about March 10, 2010 9:05 PM – by Peter [...]

  7. Semi Truck Accessories says:

    [...] Massive Drop in Number of Active Zeus C&C Servers | abuse.ch [...]

  8. You Should Talk » How To Find People For Free Using An SSN says:

    [...] Massive Drop in Number of Active Zeus C&C Servers | abuse.ch [...]

  9. Dozens of ZeuS Botnets Knocked Offline — Krebs on Security says:

    [...] activity — on the even of Mar. 9, the number of active ZeuS C&C servers he was tracking fell instantly from 249 to [...]

  10. McAfeeAvertLabs at 03/10/10 03:42:12 | Exectweets says:

    abuse.ch[...] Pro Tweets o/ “Zeus quake” http://www.abuse.ch/?p=2417 A massive drop in C&C’s as AS50215 goes dark o/ McAfeeAvertLabs – Wed 10 Mar 15:42 [...]

Trackbacks/Pingbacks


Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago